SOCLYDE logo
Current languageEN
Cybersecurity newsVulnerabilityVPNCheck Point

Check point: two critical vpn flaws to patch before exploitation

Two CVSS 9.8 vulnerabilities affect Check Point products in certain VPN configurations and may enable unauthenticated code execution.

By Soclyde Team

Technician working on a network appliance in a small-business IT room

In summary

  • CVE-2026-85102 and CVE-2026-85103 are rated CVSS 9.8 and involve VPN certificate handling.
  • Check Point says unauthenticated code execution is possible under specific conditions, with no known exploitation at disclosure.
  • Organizations should identify exposed gateways, apply the relevant Jumbo Hotfix or Live Patch and review logs.

Explore next

Soclyde resources

Article contents

On September 9, 2026, Check Point disclosed two critical vulnerabilities involving VPN certificate handling: CVE-2026-85102 and CVE-2026-85103. Both are rated 9.8 and may allow unauthenticated remote code execution under specific conditions.

Check Point says it discovered the flaws and has no indication of exploitation. For an exposed gateway, that does not replace patching: a VPN concentrates privileged access at the edge of the organization.

What the two CVEs cover

The advisories describe improper certificate-trust validation during VPN negotiation and a certificate ASN.1 decoding issue. Exact products and versions depend on configuration and the published fixes.

Teams should start from the real inventory, not a generic product name. Identify Security Gateways, management servers and Spark Firewalls, then check whether Remote Access VPN or Site-to-Site VPN is enabled.

Why a 9.8 rating matters

A critical flaw in perimeter equipment can provide a direct path into internal infrastructure. “Under specific conditions” does not make a device safe without checking its version, VPN role and applied protections.

Priority actions

Apply the Jumbo Hotfix or Live Patch specified for the deployed version. Record the change time, verify the gateway runs the intended version and remove unused images or configurations.

Before and after patching, review unusual VPN connections, account creation, configuration changes and certificate errors. An anomaly should trigger investigation, not only reinstallation.

If patching must wait

Reduce exposure, restrict allowed users and networks, disable unnecessary VPN functions and increase monitoring. These temporary steps do not replace the official fix.

The Soclyde connection

Soclyde cannot patch a Check Point appliance. It helps manage secrets associated with VPN and administrator access: unique secrets, encrypted storage and fast rotation after suspected access.

Takeaway

The two CVSS 9.8 Check Point CVEs affect VPN equipment at the network edge. Even without known exploitation, inventory, official patching and log review should be treated as urgent.

Read our team password security guide · Contact Soclyde

Frequently asked questions

Are these flaws actively exploited?

Check Point says it has no indication of exploitation. That may change and is not a reason to delay patching an exposed gateway.

Which products should be checked?

Review affected Security Gateways, Security Management Server and Spark Firewall deployments using Remote Access VPN or Site-to-Site VPN, according to Check Point’s version guidance.

What if patching cannot happen immediately?

Reduce exposure, restrict VPN access, monitor logs and follow official mitigations until the correct fix is installed.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading