Active Exploitation Imminent: Two Critical Check Point Flaws (CVE-2026-85102, CVE-2026-85103) Allow Unauthenticated Remote Code Execution on VPN-Enabled Security Gateways and Management Appliances
CVE-2026-85102 and CVE-2026-85103 are critical vulnerabilities in Check Point VPN products that can allow unauthenticated remote code execution. The first flaw involves improper validation of certificate data during VPN negotiation on Security Gateways and Spark Firewalls using Site-to-Site or Remote Access VPN. The second is a heap overflow in ASN.1 certificate decoding that can affect Security Gateways, Security Management Servers, and Spark Firewalls. This article covers how the issues work, the affected products and versions, available LivePatch and Jumbo Hotfix fixes, and temporary Site-to-Site VPN mitigations.
Summary
Check Point has published fixes for two critical VPN-related vulnerabilities. CVE-2026-85102 involves improper validation of certificate data during VPN negotiation and may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway. CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoding flow that may allow a remote attacker to execute arbitrary code on the Security Management Server and Security Gateway. Both also apply to Check Point Spark Firewall where listed. LivePatch Take 24 and specific Jumbo Hotfix / Spark builds address the issues. R82.20 is not affected.
Vulnerability Details
| CVE ID | CVSS Score | EPSS Score | Type |
|---|---|---|---|
| CVE-2026-85102 | 9.8 | 0.33% | Improper certificate validation during VPN negotiation |
| CVE-2026-85103 | 9.8 | 0.36% | Heap overflow in VPN certificate ASN.1 decoding |
Technical Information
CVE-2026-85102 — Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN
This issue is caused by improper validation of certificate data during VPN negotiation. When a peer presents certificate material as part of establishing a Remote Access or Site-to-Site VPN session, incomplete or incorrect trust checks can allow the negotiation path to be abused.
An unauthenticated remote attacker who can reach the VPN service may send crafted certificate-related input during negotiation and achieve arbitrary code execution on the Security Gateway. No prior account or user interaction is required.
The vulnerability applies to Security Gateway and Check Point Spark Firewall deployments that use Site-to-Site VPN or Remote Access VPN. Any network path that exposes those VPN services to untrusted peers is part of the attack surface.
CVE-2026-85103 — ASN.1 Decoding Heap Overflow Leading to Remote Code Execution
This issue is a heap-based buffer overflow in the ASN.1 decoding logic used for VPN certificates. ASN.1 is the encoding format commonly used in certificate structures; a flaw while parsing that data can corrupt heap memory.
An unauthenticated remote attacker can trigger the overflow by supplying crafted certificate data to the vulnerable decoding path, which may lead to arbitrary code execution. The official description covers Check Point Quantum Security Management and Quantum Security Gateway systems; Check Point Spark Firewall is also listed as affected in the vendor advisory.
Because the flaw sits in certificate processing rather than only in gateway VPN negotiation, both management and gateway roles are in scope for this CVE, unlike CVE-2026-85102, which is focused on Security Gateway and Spark Firewall VPN use cases.
Affected Products
CVE-2026-85102
- Security Gateway
- Check Point Spark Firewall (Centrally Managed)
- Check Point Spark Firewall (Locally Managed)
Applies when Site-to-Site VPN or Remote Access VPN is used.
CVE-2026-85103
- Security Management Server
- Security Gateway
- Check Point Spark Firewall (Centrally Managed)
- Check Point Spark Firewall (Locally Managed)
Affected and Fixed Versions
Both vulnerabilities affect:
- R81.20, R82, R82.10
- R81.10.x, R82.00.x
- R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10 (all end-of-support)
R82.20 is not affected.
The issues are fixed in:
- Check Point LivePatch Take 24 for R81.20, R82, and R82.10
- Jumbo Hotfix Accumulator for R82.10 starting from Take 44
- Jumbo Hotfix Accumulator for R82 starting from Take 126
- Jumbo Hotfix Accumulator for R81.20 starting from Take 166
- Check Point Spark Firewalls R82.00.10 starting from Build 2325
- Check Point Spark Firewalls R81.10.17 starting from Build 4968
If automatic installation of Check Point LivePatch is enabled on R81.20, R82, or R82.10, the protection is applied automatically. Otherwise, install the offline LivePatch package for your version or move to a fixed Jumbo Hotfix / Spark build.
Impact
-
CVE-2026-85102Unauthenticated remote code execution on the Security Gateway (and affected Spark Firewall with Site-to-Site or Remote Access VPN).
-
CVE-2026-85103Remote code execution on the Security Management Server and Security Gateway (and Check Point Spark Firewall).
MITRE ATT&CK Mapping
| Technique ID | Technique Name | Tactic |
|---|---|---|
| T1190 | Exploit Public-Facing Application | Initial Access |
| T1210 | Exploitation of Remote Services | Lateral Movement |
Mitigation and Recommendations
Install a fixed release or LivePatch as soon as possible.
LivePatch validation
On a Security Gateway or ClusterXL member in Expert mode, run cpinfo -y CPupdates and confirm the urgent security update take is present (Take 24 for the supported trains above). For LivePatch status, run cplp list (or g_all cplp list on a Scalable Platform Security Group). Expected output includes cpcert module entries covering CVE-2026-85102 and CVE-2026-85103.
Temporary mitigation (Site-to-Site VPN)
Disable implied rules for VPN and manually define VPN access for UDP/500 and UDP/4500 for specific peer IP addresses only. This mitigation is not applicable to locally managed Spark Firewall.
- Apply LivePatch Take 24 or the matching Jumbo Hotfix / Spark build for your version.
- Validate with
cpinfo -y CPupdatesandcplp list. - For Site-to-Site VPN, restrict UDP/500 and UDP/4500 to trusted peer IPs where the temporary mitigation applies.
Apply fixed software or LivePatch promptly. Until then, use the Site-to-Site VPN mitigation where applicable, and confirm LivePatch status on supported versions.
Instantly Fix Risks with Saner Patch Management
Saner patch management is a continuous, automated, and integrated solution that helps you quickly remediate risks, including critical network infrastructure updates. It supports Windows, Linux, macOS, and 550+ third-party applications.
You can stage patches in a safe testing environment before production deployment and roll back if needed.
Experience the fastest and most accurate patching software here.




