Security bulletin with an exclamation point in the middle of the screen
Security bulletin with an exclamation point in the middle of the screen

Check Point VPN Critical RCE Vulnerabilities CVE-2026-85102 & CVE-2026-85103

Learn about CVE-2026-85102 and CVE-2026-85103, two critical Check Point VPN vulnerabilities that could allow unauthenticated remote code execution on exposed gateways and firewalls.
Security bulletin with an exclamation point in the middle of the screen
6 min read

Threat Summary

Patches have now been released addressing two critical vulnerabilities: CVE-2026-85102, which affects Security Gateway and Spark Firewall, and CVE-2026-85103, which affects Security Gateway, Management Server, and Spark Firewall.

CVE-2026-85102 is an improper certificate validation during VPN negotiation and CVE-2026-85103 heap overflow in ASN.1 certificate decoding. Both bugs open the door to unauthenticated remote code execution (RCE), offering attackers potential full control over targeted devices. These vulnerabilities were discovered internally by Check Point and first disclosed on September 7, 2026, and updated in their Advisory on September 9th, 2026. These flaws have been rated CVSS v3.1 9.8 (Critical: network exploitable, no user interaction, no privileges required).

All modern Check Point VPN deployments (R80–R82.10 and related Spark Firewall builds) are exposed if they remain unpatched, particularly those providing Remote Access or Site-to-Site VPN services at the network perimeter. At the time of writing, no active in-the-wild exploitation or public proof-of-concept (PoC) code is known. The Dutch NCSC assesses that exploitation attempts can be expected soon. CERT-EU has issued an urgent advisory recommending immediate patching of internet-facing appliances. Prominent government agencies and industry threat monitors concur that urgent remediation is necessary to avoid compromise.

Check Point has delivered immediate patches via LivePatch (automatic for enrolled customers) and Jumbo Hotfix tracks for all major product lines. To date, CISA has not added these vulnerabilities to the US federal Known Exploited Vulnerabilities (KEV) Catalog, but this may change quickly, given the severity of the vulnerabilities.

All organizations should assume hostile actors will attempt exploitation once viable methods emerge, and must take swift action to patch, restrict, and monitor access.

Recommendations for CVE-2026-85102 & CVE-2026-85103 

Patch All Affected Systems:

  • If using Check Point LivePatch, confirm protection is active (LivePatch Take 24 or later) on all gateways and management servers.
  • If LivePatch is not deployed, manually install the applicable Jumbo Hotfix Accumulator:
    • 20: Take 166 or later
    • R82: Take 126 or later
    • 10: Take 44 or later
    • Spark Firewall: R82.00.10 Build 2325+ or R81.10.17 Build 4968+
  • Validate patch status on the appliances.

Restrict and Harden VPN Access:

  • For Site-to-Site VPN: Disable implied VPN rules and explicitly allow only trusted peer IPs for UDP/500, UDP/4500.
  • For Remote Access VPN and Spark: If patching isn’t possible immediately, treat these systems as exposed and accelerate remediation.
  • Restrict remote and management interfaces to trusted networks/subnets only

Long-Term Measures:

  • Review and enforce strong segmentation between critical networks and VPN infrastructure.
  • Maintain a robust vulnerability management and patch testing regimen for all perimeter and remote access infrastructure.
  • Enable and regularly test Secure Configuration Verification (SCV) for VPN clients.
  • Migrate away from deprecated protocols (e.g., IKEv1) and ensure usage of strong cryptographic standards.

Temporary Workarounds

Note that all workarounds are temporary, do not fully mitigate risk, and must be considered stopgaps only until comprehensive patching is completed.

Site-to-Site VPN Exposure

Until patching is complete:

  • Disable implied VPN access rules and restrict IKE/IPsec traffic (UDP/500, UDP/4500) to known peer IPs only.
  • Note: This provides only partial risk reduction and does NOT secure Remote Access VPN or locally managed Spark Firewalls.

No Reliable Workaround for Remote Access VPN/Spark

  • These configurations are fully exposed unless patched; prioritize applying vendor fixes as soon as possible.
  • All workarounds are temporary, do not fully mitigate risk, and must be considered stopgaps only until comprehensive patching is completed.

References:

 

Share this post: