Check Point twin CVSS 9.8s in VPN certificate path (CVE-2026-85102 / 85103)

By George Bailey   Published: 09/10/26   Updated: 09/10/26   2 min read

What Changed

Check Point disclosed on September 9, 2026 two critical flaws in VPN certificate handling on Quantum Security Gateway and Security Management products (with Spark deployments called out in secondary advisories). CVE-2026-85102 is improper validation of certificate data during VPN negotiation. CVE-2026-85103 is a heap overflow in VPN certificate ASN.1 decoding. Both carry vendor-assigned CVSS 9.8 scores and can allow unauthenticated remote code execution “under specific conditions” Check Point has not fully detailed publicly. Vendor documents: sk1000117 and sk1000118.

There is no confirmed in-the-wild exploitation as of disclosure. Check Point says it found both issues internally and has not published IoCs because it has seen no evidence of external exploitation. R82.20 is not affected. Remediation on supported branches is LivePatch Take 24 (rollout began September 9) and/or the latest Jumbo Hotfix Accumulator for the deployed release. Public CVE text commonly marks R82.10 Jumbo Take 43 or below, R82 Take 125 or below, and R81.20 Take 165 or below as affected. End-of-support R80 through R81.10 need an upgrade to a fixed supported release.

Why This Matters Operationally

Two remote unauthenticated RCEs in the same certificate path put VPN negotiation—the code that must parse untrusted peer material before a session is fully trusted—on the same management-plane risk pattern as this week’s firewall and ERP kernel stories. Even without confirmed exploitation, Check Point’s 2026 track record on this product family argues for same-week LivePatch or Jumbo, not a wait-and-see. CVE-2026-85103’s reach into Security Management widens blast radius beyond the gateway dataplane.

What Defenders Should Verify First

Source Context

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.