Check Point Patches Two Critical VPN Certificate Flaws Amid Exploitation Warning
What happened
Check Point disclosed two critical vulnerabilities affecting how its firewall and security management products validate and process VPN certificates. Both were assigned a CVSS score of 9.8 by the vendor and, under conditions Check Point has not publicly detailed, could allow an unauthenticated remote attacker to execute code. Check Point says it discovered both issues internally and has seen no evidence of exploitation at the time of disclosure, and began shipping fixes the same day via its Live Patch mechanism and Jumbo Hotfixes. Shortly after, the Dutch National Cyber Security Centre (NCSC) issued its own advisory assessing the likelihood of exploitation as high and stating it expects exploitation attempts "soon," despite the absence of a known public proof-of-concept at this time. This is the third time in as many months that Check Point has patched a critical, unauthenticated remote-code-execution-class flaw in its VPN or management stack, following incidents in June and July that were confirmed as actively exploited at disclosure.
Who is affected
The first flaw affects Check Point Security Gateways (the firewall appliances that terminate VPN connections). The second affects both Security Gateways and the Security Management Server, the console administrators use to configure gateway fleets. Affected product lines include the R81.20, R82, R82.10, and R81.10.x branches, R82.00.x, and the Spark small-business firewall line, as well as end-of-support versions R80 through R80.40, R81, and R81.10. Version R82.20 is confirmed not affected. Organizations using the Site-to-Site VPN component are specifically called out in Check Point's guidance as needing additional configuration review.
Why it matters
VPN gateways and their management consoles are internet-facing by design and sit directly on the network perimeter, making unauthenticated remote code execution against them one of the highest-impact vulnerability classes possible: successful exploitation could hand an attacker full control of the gateway, visibility into encrypted traffic, and a foothold from which to move into the internal network. The fact that a national CERT is publicly flagging "imminent" exploitation before any known proof-of-concept exists reflects both the severity of the flaws and the pattern of rapid, real-world targeting that has followed several recent Check Point VPN disclosures. Organizations that delay patching perimeter VPN infrastructure have historically been the first ones affected once exploit code becomes available.
Technical details
- CVE-2026-85102 — CVSS 9.8. Improper validation of certificate trust during VPN negotiation; may allow a remote, unauthenticated attacker to execute code on the Security Gateway.
- CVE-2026-85103 — CVSS 9.8. Heap-based buffer overflow in the VPN certificate ASN.1 decoder; may allow remote code execution on both Security Gateway and Security Management Server systems.
- Affected: R81.20 (Jumbo Hotfix Take 165 or below), R82 (Take 125 or below), R82.10 (Take 43 or below), plus R81.10.x, R82.00.x, Spark, and end-of-support R80–R81.10 branches.
- Fixed via: Check Point Live Patch Take 24 (R81.20, R82, R82.10), or Jumbo Hotfix Accumulators — R82.10 Take 44+, R82 Take 126+, R81.20 Take 166+, Spark R82.00.10 Build 2325+, Spark R81.10.17 Build 4968+.
- Exploitation status: No public proof-of-concept and no confirmed in-the-wild exploitation as of disclosure; Dutch NCSC assesses exploitation likelihood as high and expects attempts soon.
Recommended actions
- Confirm whether Check Point Live Patch (CPLP) has automatically applied protections to your R81.20, R82, or R82.10 gateways; CPLP does not cover all versions or configurations, so verify coverage explicitly rather than assuming protection.
- Where Live Patch is not available or does not apply, install the latest Jumbo Hotfix Accumulator for your deployed version as soon as possible.
- For Site-to-Site VPN deployments, restrict VPN rules to specific, trusted IP addresses as an interim mitigation while patching is completed.
- Prioritize any end-of-support R80–R81.10 systems for migration, since they no longer receive standard security updates and represent long-term exposure.
- Monitor Check Point community advisories (sk1000117 and sk1000118) and your national CERT for updated indicators of compromise or confirmation of active exploitation.
- Review VPN gateway and management server logs for anomalous certificate-related errors or crashes that could indicate exploitation attempts, even in the absence of published IOCs.
Sources
- https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html
- https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/
