Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks
Check Point patched two critical VPN flaws, CVE-2026-85102 and CVE-2026-85103 (CVSS 9.8), allowing unauthenticated RCE on Security Gateways.
Check Point disclosed and patched two critical VPN vulnerabilities, CVE-2026-85102 (improper certificate trust validation, CWE-295) and CVE-2026-85103 (heap-based buffer overflow in ASN.1 certificate parsing, CWE-122), both rated CVSS 9.8 and exploitable for unauthenticated remote code execution under specific conditions. The flaws affect Security Gateway, Security Management Server, and Spark Firewall deployments on R81.20, R82, and R82.10 branches plus end-of-support versions such as R80.40 and R81, while R82.20 is not affected. Check Point reports no evidence of active exploitation or public PoC; Live Patch rollout began September 9, 2026, and administrators without it must install Jumbo Hotfix Accumulator builds (R82.10 Take 44+, R82 Take 126+, R81.20 Take 166+). For Site-to-Site VPN, restricting UDP ports 500 and 4500 to known peers serves as an interim workaround, but no mitigation exists for Remote Access VPN or Spark Firewalls.
- CVE-2026-85102 stems from improper certificate trust validation (CWE-295) during VPN negotiation, enabling unauthenticated RCE.
- CVE-2026-85103 is a heap-based buffer overflow (CWE-122) triggered by malicious certificates on gateways and management servers.
- No evidence of exploitation or public PoC; flaws are unrelated to the actively exploited IKEv1 bypass CVE-2026-50751.
- Live Patch users received protection automatically from September 9, 2026; others need manual hotfixes.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-50751 | Unauthenticated IKEv1 VPN Auth Bypass in Check Point Security Gateways Check Point has disclosed CVE-2026-50751, a critical (CVSS 9.3) improper authentication flaw (CWE-287) in the certificate validation logic for Remote Access and Mobile Access VPN when the deprecated IKEv1 key exchange is used. An unauthenticated remote attacker can exploit this logic flow weakness during IKEv1 negotiation to bypass user authentication entirely. Successful exploitation lets the attacker establish a remote access VPN connection without a valid user password, gaining access to the organization's internal network resources (high confidentiality impact per the CVSS score). Any organization running a Check Point Security Gateway on Gaia OS or Gaia Embedded with IKEv1-based Remote Access/Mobile Access configured is affected; specific affected and fixed versions are in Check Point's advisory. The flaw is being exploited in the wild — it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-08 with known ransomware use and an EPSS of 83.8% — and it was disclosed alongside other critical Check Point VPN certificate flaws per recent headlines. Do: Upgrade affected Security Gateways to the fixed releases identified in Check Point's advisory (version numbers are not specified in the source data), prioritizing internet-facing VPN gateways; as an interim mitigation, move Remote Access/Mobile Access clients to IKEv2 or disable IKEv1. Review VPN authentication logs for sessions established without valid credentials, given known in-the-wild and ransomware exploitation. Federal agencies must apply mitigations per BOD 22-01, and defenders should beware of fake 'public PoC' repositories spreading malware (ChocoPoC RAT), since no legitimate public PoC is known. | 9.3 | 84% | KEV ransomware PoC |
| massplausibly on the order of 100,000+ internet-exposed Check Point gateways, with the IKEv1-affected subset likely tens of thousands of sites (estimate) | |
| CVE-2026-85102 | Unauthenticated RCE in Check Point Quantum Security Gateway via certificate flaw CVE-2026-85102 is an improper certificate trust-validation flaw (CWE-295) in the VPN negotiation code of Check Point Quantum Security Gateways. An unauthenticated remote attacker who can reach the gateway's VPN service can trigger the flaw during VPN negotiation, where certificates involved in the exchange are not properly validated, and achieve code execution on the gateway. Successful exploitation yields arbitrary code execution on the gateway with high impact on confidentiality, integrity, and availability (CVSS 9.8), amounting to full compromise of the security gateway. The affected population is organizations running Quantum Security Gateways with VPN services reachable from untrusted networks. As of the available reporting there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation is confirmed; the issue was disclosed alongside a second, similarly rated (9.8) Check Point VPN certificate-validation RCE flaw. Do: Upgrade Quantum Security Gateways to the fixed versions listed in Check Point's advisory (AV26-902) as soon as they are published, prioritizing internet-facing VPN gateways. Until patched, restrict exposure of VPN negotiation endpoints to trusted networks and monitor VPN services for anomalous handshake activity. Inventory which gateways in your estate expose VPN services publicly and treat those as the highest-priority targets. | 9.8 | — |
| largetens of thousands of internet-exposed Quantum VPN gateways (est.); total Check Point installed base plausibly in the hundreds of thousands of appliances/sites | ||
| CVE-2026-85103 | Unauthenticated RCE in Check Point Quantum VPN Certificate ASN.1 Decoding CVE-2026-85103 is a heap-based buffer overflow (CWE-122) in the ASN.1 certificate-decoding code used by Check Point's VPN implementation, rated 9.8 Critical with a network-exploitable, unauthenticated, low-complexity vector. An unauthenticated remote attacker can trigger the flaw by sending crafted certificate data that the VPN service parses during connection handling, causing heap corruption that allows arbitrary code execution on the target system. Successful exploitation grants the attacker code execution with high confidentiality, integrity, and availability impact, which on security gateways and management servers could mean control of the security infrastructure itself. Any organization running Check Point Quantum Security Management or Quantum Security Gateway systems that process VPN certificate traffic is potentially affected, and the advisory set indicates this flaw was disclosed alongside a second, similarly rated 9.8 VPN certificate vulnerability (Check Point advisory AV26-902). There is no evidence of exploitation so far: the flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known. Do: Patch promptly: because this is an unauthenticated, network-reachable 9.8-rated RCE in the VPN path, upgrade Quantum Security Management and Quantum Security Gateway deployments per Check Point's advisory (referenced as AV26-902), and check your current software versions against the affected/fixed ranges listed there, which are not specified in the data available here. Until patched, restrict access to exposed VPN and management interfaces to trusted source IPs where possible and monitor VPN endpoints for anomalous connection or crash behavior. Inventory all Quantum appliances and management servers, since the flaw affects both product lines and was disclosed together with a second 9.8 VPN certificate flaw. | 9.8 | — |
| largelikely tens of thousands (order of magnitude 10k–100k) of deployed Quantum gateways/management servers, of which a substantial share expose VPN endpoints to… |
Full article464 words · extracted from cybersecuritynews.com · click to collapse
Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score of 9.8 and both capable of allowing unauthenticated remote code execution under specific conditions.
Check Point’s own research team uncovered the flaws, and the company says it has found no evidence of active exploitation or public proof-of-concept code as of this writing.
Check Point VPN Vulnerabilities
CVE-2026-85102 is rooted in improper certificate trust validation during VPN negotiation, tracked under CWE-295. According to Check Point’s advisory sk1000117, the flaw fails to properly validate the trust of a presented certificate, letting an unauthenticated attacker push VPN negotiation far enough to execute arbitrary code on the Security Gateway. This affects both Remote Access VPN and Site-to-Site VPN configurations.
CVE-2026-85103, by contrast, is a heap-based buffer overflow (CWE-122) that occurs while the product parses the ASN.1 structure of a VPN certificate. Detailed in advisory sk1000118, this bug lets a remote attacker trigger the overflow simply by sending a malicious certificate, potentially achieving code execution on both Quantum Security Gateway and Quantum Security Management systems.
The vulnerabilities affect Check Point Security Gateway, Security Management Server, and Spark Firewall deployments across multiple release branches, including R81.20, R82, and R82.10 with Jumbo Hotfix Takes below the newly patched builds, along with several end-of-support versions such as R80.40 and R81. Check Point has confirmed that R82.20 is not affected.
Notably, CVE-2026-85102 primarily impacts Security Gateways engaged in VPN connections, while CVE-2026-85103 spans both gateway and management infrastructure.
Organizations using Check Point Live Patch benefit automatically, since the protective rollout began on September 9, 2026. Administrators without Live Patch enabled must manually install the latest Jumbo Hotfix Accumulator for their branch, specifically R82.10 Take 44 or higher, R82 Take 126 or higher, or R81.20 Take 166 or higher, along with dedicated Spark Firewall builds.
For Site-to-Site VPN deployments that cannot patch immediately, Check Point recommends disabling implied VPN rules and restricting UDP ports 500 and 4500 to known peer IP addresses, though this workaround does not extend to Remote Access VPN, and no interim mitigation exists for locally managed Spark Firewalls.
These newly patched bugs are unrelated to the actively exploited CVE-2026-50751, an IKEv1 authentication bypass tied to Qilin ransomware activity disclosed earlier this year.
Given the critical severity and network-exploitable nature of both new flaws, security teams running Check Point infrastructure should prioritize patching immediately rather than waiting for confirmed in-the-wild exploitation.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/check-point-vpn-vulnerabilities/