Check Point Patches Critical VPN Flaws: Remote Code Execution Risk Addressed
September 10, 2026
Two critical VPN vulnerabilities disclosed by Check Point, CVE-2026-85102 and CVE-2026-85103, could allow unauthenticated remote code execution on Security Gateway and Security Management Server unless patched.
CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoding flow affecting Security Management Server, Security Gateway, and Spark Firewall.
CVE-2026-85102 involves improper validation of certificate data during VPN negotiation and impacts Security Gateway and Spark Firewall using Site-to-Site or Remote Access VPN.
Mitigations include a Live Patch rollout for compatible versions (R81.20, R82.00, R82.10) and Jumbo Hotfix deployments, though some older branches may lack patches.
There is no evidence of active exploitation yet, but the time between disclosure and exploitation is shrinking, increasing urgency to patch.
Users report download and patch rollout timing issues, with questions about mitigations for environments not ready to patch and VPN-related mitigation impacts on remote users.
The report references prior Check Point zero-day warnings from the summer and provides context and links to related security news.
Patches are released for R82.10, R82, and R81.20 across affected products; mitigation includes manually defining VPN rules.
Check Point has not published IOCs; it’s unclear which specific Spark or Security Management versions are affected or what exact trigger conditions are, with remediation guidance in advisories sk1000117 and sk1000118.
A fix requires upgrading to a supported version, with R82.20 reportedly not affected.
Experts compare this to other 2026 incidents, highlighting rapid exploitation post-disclosure and the need for faster patch adoption.
Experts warn that delaying patching to await KEV listings or confirmed exploits is risky since unauthenticated RCE at the gateway can bypass defenses and expose the organization.
Summary based on 4 sources
Get a daily email with more Tech stories
Sources

The Hacker News • Sep 10, 2026
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
SecurityWeek • Sep 11, 2026
Check Point Patches Critical VPN Vulnerabilities
SC Media • Sep 11, 2026
Check Point patches two critical VPN gateway bugs