On September 9, 2026, Check Point disclosed two critical vulnerabilities involving VPN certificate handling: CVE-2026-85102 and CVE-2026-85103. Both are rated 9.8 and may allow unauthenticated remote code execution under specific conditions.
Check Point says it discovered the flaws and has no indication of exploitation. For an exposed gateway, that does not replace patching: a VPN concentrates privileged access at the edge of the organization.
What the two CVEs cover
The advisories describe improper certificate-trust validation during VPN negotiation and a certificate ASN.1 decoding issue. Exact products and versions depend on configuration and the published fixes.
Teams should start from the real inventory, not a generic product name. Identify Security Gateways, management servers and Spark Firewalls, then check whether Remote Access VPN or Site-to-Site VPN is enabled.
Why a 9.8 rating matters
A critical flaw in perimeter equipment can provide a direct path into internal infrastructure. “Under specific conditions” does not make a device safe without checking its version, VPN role and applied protections.
Priority actions
Apply the Jumbo Hotfix or Live Patch specified for the deployed version. Record the change time, verify the gateway runs the intended version and remove unused images or configurations.
Before and after patching, review unusual VPN connections, account creation, configuration changes and certificate errors. An anomaly should trigger investigation, not only reinstallation.
If patching must wait
Reduce exposure, restrict allowed users and networks, disable unnecessary VPN functions and increase monitoring. These temporary steps do not replace the official fix.
The Soclyde connection
Soclyde cannot patch a Check Point appliance. It helps manage secrets associated with VPN and administrator access: unique secrets, encrypted storage and fast rotation after suspected access.
Takeaway
The two CVSS 9.8 Check Point CVEs affect VPN equipment at the network edge. Even without known exploitation, inventory, official patching and log review should be treated as urgent.



