SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Active Exploitation Imminent: Two Critical Check Point Flaws (CVE-2026-85102, CVE-2026-85103) Allow Unauthenticated Remote Code Execution on VPN-Enabled Security Gateways and Management Appliances

Active Exploitation Imminent: Two Critical Check Point Flaws (CVE-2026-85102, CVE-2026-85103) Allow Unauthenticated Remote Code Execution on VPN-Enabled Security Gateways and Management Appliances

CVE-2026-85102 and CVE-2026-85103 are critical vulnerabilities in Check Point VPN products that can allow unauthenticated remote code execution. The first flaw involves improper validation of certificate data during VPN negotiation on Security Gateways and Spark Firewalls using Site-to-Site or Remote Access VPN. The second is a heap overflow in ASN.1 certificate decoding that can affect Security Gateways, Security Management Servers, and Spark Firewalls. This article covers how the issues work, the affected products and versions, available LivePatch and Jumbo Hotfix fixes, and temporary Site-to-Site VPN mitigations.

Sep 15, 2026By Bapanapalli Prem Sai Siddhik

Summary

Check Point has published fixes for two critical VPN-related vulnerabilities. CVE-2026-85102 involves improper validation of certificate data during VPN negotiation and may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway. CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoding flow that may allow a remote attacker to execute arbitrary code on the Security Management Server and Security Gateway. Both also apply to Check Point Spark Firewall where listed. LivePatch Take 24 and specific Jumbo Hotfix / Spark builds address the issues. R82.20 is not affected.

Vulnerability Details

CVE ID CVSS Score EPSS Score Type
CVE-2026-85102 9.8 0.33% Improper certificate validation during VPN negotiation
CVE-2026-85103 9.8 0.36% Heap overflow in VPN certificate ASN.1 decoding

Technical Information

Critical Unauthenticated Network Access

CVE-2026-85102 — Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN

This issue is caused by improper validation of certificate data during VPN negotiation. When a peer presents certificate material as part of establishing a Remote Access or Site-to-Site VPN session, incomplete or incorrect trust checks can allow the negotiation path to be abused.

An unauthenticated remote attacker who can reach the VPN service may send crafted certificate-related input during negotiation and achieve arbitrary code execution on the Security Gateway. No prior account or user interaction is required.

The vulnerability applies to Security Gateway and Check Point Spark Firewall deployments that use Site-to-Site VPN or Remote Access VPN. Any network path that exposes those VPN services to untrusted peers is part of the attack surface.

Critical Unauthenticated Network Access

CVE-2026-85103 — ASN.1 Decoding Heap Overflow Leading to Remote Code Execution

This issue is a heap-based buffer overflow in the ASN.1 decoding logic used for VPN certificates. ASN.1 is the encoding format commonly used in certificate structures; a flaw while parsing that data can corrupt heap memory.

An unauthenticated remote attacker can trigger the overflow by supplying crafted certificate data to the vulnerable decoding path, which may lead to arbitrary code execution. The official description covers Check Point Quantum Security Management and Quantum Security Gateway systems; Check Point Spark Firewall is also listed as affected in the vendor advisory.

Because the flaw sits in certificate processing rather than only in gateway VPN negotiation, both management and gateway roles are in scope for this CVE, unlike CVE-2026-85102, which is focused on Security Gateway and Spark Firewall VPN use cases.

Affected Products

CVE-2026-85102

  • Security Gateway
  • Check Point Spark Firewall (Centrally Managed)
  • Check Point Spark Firewall (Locally Managed)

Applies when Site-to-Site VPN or Remote Access VPN is used.

CVE-2026-85103

  • Security Management Server
  • Security Gateway
  • Check Point Spark Firewall (Centrally Managed)
  • Check Point Spark Firewall (Locally Managed)

Affected and Fixed Versions

Both vulnerabilities affect:

  • R81.20, R82, R82.10
  • R81.10.x, R82.00.x
  • R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10 (all end-of-support)

R82.20 is not affected.

The issues are fixed in:

  • Check Point LivePatch Take 24 for R81.20, R82, and R82.10
  • Jumbo Hotfix Accumulator for R82.10 starting from Take 44
  • Jumbo Hotfix Accumulator for R82 starting from Take 126
  • Jumbo Hotfix Accumulator for R81.20 starting from Take 166
  • Check Point Spark Firewalls R82.00.10 starting from Build 2325
  • Check Point Spark Firewalls R81.10.17 starting from Build 4968

If automatic installation of Check Point LivePatch is enabled on R81.20, R82, or R82.10, the protection is applied automatically. Otherwise, install the offline LivePatch package for your version or move to a fixed Jumbo Hotfix / Spark build.

Impact

  • CVE-2026-85102
    Unauthenticated remote code execution on the Security Gateway (and affected Spark Firewall with Site-to-Site or Remote Access VPN).
  • CVE-2026-85103
    Remote code execution on the Security Management Server and Security Gateway (and Check Point Spark Firewall).

MITRE ATT&CK Mapping

Technique ID Technique Name Tactic
T1190 Exploit Public-Facing Application Initial Access
T1210 Exploitation of Remote Services Lateral Movement

Mitigation and Recommendations

Install a fixed release or LivePatch as soon as possible.

LivePatch validation

On a Security Gateway or ClusterXL member in Expert mode, run cpinfo -y CPupdates and confirm the urgent security update take is present (Take 24 for the supported trains above). For LivePatch status, run cplp list (or g_all cplp list on a Scalable Platform Security Group). Expected output includes cpcert module entries covering CVE-2026-85102 and CVE-2026-85103.

Temporary mitigation (Site-to-Site VPN)

Disable implied rules for VPN and manually define VPN access for UDP/500 and UDP/4500 for specific peer IP addresses only. This mitigation is not applicable to locally managed Spark Firewall.

  • Apply LivePatch Take 24 or the matching Jumbo Hotfix / Spark build for your version.
  • Validate with cpinfo -y CPupdates and cplp list.
  • For Site-to-Site VPN, restrict UDP/500 and UDP/4500 to trusted peer IPs where the temporary mitigation applies.

Apply fixed software or LivePatch promptly. Until then, use the Site-to-Site VPN mitigation where applicable, and confirm LivePatch status on supported versions.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated solution that helps you quickly remediate risks, including critical network infrastructure updates. It supports Windows, Linux, macOS, and 550+ third-party applications.

You can stage patches in a safe testing environment before production deployment and roll back if needed.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Cisco FMC Zero-Day Under Active Attack: UAT-12197, UAT-11823 and Qilin-Linked UAT-11988 Exploit Firewall Flaws
Cisco FMC Zero-Day Under Active Attack: UAT-12197, UAT-11823 and Qilin-Linked UAT-11988 Exploit Firewall Flaws

CVE Research

Cisco FMC Zero-Day Under Active Attack: UAT-12197, UAT-11823 and Qilin-Linked UAT-11988 Exploit Firewall Flaws

Sep 11, 2026

Open CVE-2026-87491: Google Patches Seventh Actively Exploited Chrome Zero-Day of 2026
CVE-2026-87491: Google Fixes 7th Exploited Chrome Zero-Day of 2026

CVE Research

CVE-2026-87491: Google Patches Seventh Actively Exploited Chrome Zero-Day of 2026

Sep 10, 2026

Open Microsoft's September 2026 Patch Tuesday: 973 Vulnerabilities, Two Exploited Zero-Days and a Record Security Release
Microsoft's September 2026 Patch Tuesday: 973 Vulnerabilities, Two Exploited Zero-Days and a Record Security Release

CVE Research

Microsoft's September 2026 Patch Tuesday: 973 Vulnerabilities, Two Exploited Zero-Days and a Record Security Release

Microsoft's September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Office, infrastructure services, virtualization components and other Microsoft products.

Sep 9, 2026

Open MikroTik RouterOS Under Attack: Critical SSH Vulnerabilities Enable Router Takeover
MikroTik RouterOS Under Attack: Critical SSH Vulnerabilities Enable Router Takeover

CVE Research

MikroTik RouterOS Under Attack: Critical SSH Vulnerabilities Enable Router Takeover

Sep 8, 2026