ZeroHour
Story · 7 sources · 10 articlesfirst updated ()

Dutch NCSC warns of imminent exploitation of critical Check Point VPN RCE flaws; vendor also patches pre-auth root RCE in management servers

What's new: September 9, 2026: Check Point shipped emergency fixes for CVE-2026-85102 and CVE-2026-85103 via LivePatch Take 24 and Jumbo Hotfix Accumulator takes (R82.10 Take 44, R82 Take 126, R81.20 Take 166 or later) under advisories sk1000117 and sk1000118. September 12-14, 2026: The Dutch NCSC warning drew coverage, rating exploitation likelihood and impact as high and urging immediate patching; no…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

The Dutch NCSC rates exploitation likelihood as high for two CVSS 9.8 Check Point VPN flaws (CVE-2026-85102, CVE-2026-85103) enabling unauthenticated RCE, fixed September 9, 2026 via LivePatch Take 24 and Jumbo Hotfix takes with no public PoC; Check Point…

The Dutch NCSC warned that two critical Check Point VPN flaws, CVE-2026-85102 and CVE-2026-85103 (both CVSS 9.8), allow unauthenticated remote code execution and assessed the likelihood and impact of exploitation as high, though no public exploit code has been reported. CVE-2026-85103 is a heap-based buffer overflow in the VPN certificate ASN.1 decoder affecting Security Gateways and Security Management Servers; CVE-2026-85102 is described as improper certificate (trust) validation during VPN negotiation (BleepingComputer, Cyber Security News) or a security-check bypass in the VPN negotiation process (Security Affairs). Affected releases span R81.20, R82, R82.10, R81.10.x, R82.00.x and end-of-support R80 through R81.10; R82.20 is unaffected. Check Point shipped emergency fixes on September 9, 2026 via LivePatch Take 24 and Jumbo Hotfix Accumulator takes (R82.10 Take 44, R82 Take 126, R81.20 Take 166 or later) under advisories sk1000117 and sk1000118, and NCSC recommends restricting Site-to-Site VPN rules and UDP ports 500/4500 to trusted IPs while reviewing VPN negotiation logs. Separately, Check Point patched CVE-2026-91843 (CVSS 3.1: 9.8), a stack-based buffer overflow triggered by an excessively long username in the pre-authentication login process of Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server, enabling unauthenticated root-level code execution with low complexity and no user interaction; compromise would expose management data, security policies, admin details and collected logs. Affected branches span R80 through R82.20 including end-of-support releases (Canadian advisory: R81.20 Take 166 and prior, R82 Take 126 and prior, R82.10 Take 44 and prior, and R82.20). Fixes ship via LivePatch under advisory sk1000155 with offline urgent bundles for R81.20-R82.20 (Takes 28-29); auto-update customers and Smart-1 Cloud are already protected. Check Point, CISA and SecurityWeek report no exploitation in the wild, no public PoC as of September 16, and no CISA KEV listing. Sources disagree on the attack path: The Hacker News and Security Affairs say it is reachable only through the SmartConsole Trusted Clients setting, while BleepingComputer says all Security Management Server deployments are vulnerable regardless of configuration. Censys counted 3,836 hosts presenting Check Point management identities. This is the fifth critical unauthenticated Check Point management flaw since July 22; the earlier…

  • CVE-2026-85102 and CVE-2026-85103 (both CVSS 9.8) enable unauthenticated remote code execution on Check Point VPN-enabled Quantum Security Gateways, Spark Firewalls, and Security Management Servers; the Dutch NCSC rates exploitation…
  • CVE-2026-85103 is a heap-based buffer overflow in the VPN certificate ASN.1 decoder; CVE-2026-85102 is described as improper certificate (trust) validation during VPN negotiation (BleepingComputer, Cyber Security News) or a security-check…
  • VPN flaws affect R81.20, R82, R82.10, R81.10.x, R82.00.x and end-of-support R80-R81.10; R82.20 is unaffected. Fixes shipped September 9, 2026 via LivePatch Take 24 and Jumbo Hotfix Accumulator takes (R82.10 Take 44, R82 Take 126, R81.20…
  • NCSC mitigations for the VPN flaws: restrict Site-to-Site VPN rules and UDP ports 500 and 4500 to trusted/known peer IPs, disable implied rules for Site-to-Site VPN, and review VPN negotiation logs.
  • CVE-2026-91843 (CVSS 3.1: 9.8) is a stack-based buffer overflow triggered by an excessively long username in the pre-authentication login process, granting unauthenticated remote root code execution with low complexity and no user…
  • CVE-2026-91843 affects Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server across R80-R82.20 including end-of-support releases; the Canadian advisory lists R81.20 Take 166 and prior,…
  • CVE-2026-91843 fix ships via LivePatch advisory sk1000155; offline urgent bundles for R81.20-R82.20 (Takes 28-29) were released; auto-update customers and Smart-1 Cloud are already protected.
  • No exploitation observed for CVE-2026-91843 per Check Point, CISA and SecurityWeek; no public PoC as of September 16, 2026, and not listed in CISA KEV. Attacks are detectable via 'Administrator failed to log in: Username too long' entries…

Coverage timeline

  1. · 5d ago
    BleepingComputer· 78
    Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

    Dutch NCSC warns exploitation is imminent for critical Check Point VPN RCE flaws CVE-2026-85102 and CVE-2026-85103, urging immediate patching of Security Gateways.

  2. · 4d ago
    Cyber Security News· 74
    NCSC Warns of Critical Check Point VPN Flaws as Large-Scale Exploitation Is Expected

    Dutch NCSC warns of two critical CVSS 9.8 Check Point VPN flaws enabling unauthenticated remote code execution, urging immediate patching before mass exploitation.

  3. · 4d ago
    Security Affairs· 68
    Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk

    Dutch NCSC warns two CVSS 9.8 Check Point VPN flaws enable unauthenticated RCE; patch and restrict access before exploitation begins.

  4. · 1d ago
    Cyber Security News· 70
    Check Point Vulnerability Lets Remote Hackers Gain Root Access Without Authentication

    Check Point patched CVE-2026-91843, a CVSS 9.8 pre-auth stack overflow granting remote root on Security Management and Log Servers.

  5. · 1d ago
    GBHackers· 72
    Critical Check Point Vulnerability Allows Remote Root Code Execution Without Authentication

    Check Point patched CVE-2026-91843 (CVSS 9.8), an unauthenticated stack overflow enabling remote root code execution on Security Management and Log Servers.

  6. · 18h ago
    The Hacker News· 66
    Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

    Check Point patched CVE-2026-91843 (CVSS 9.8), a pre-authentication stack overflow letting unauthenticated attackers run code as root on Security Management and Log Servers.

  7. · 18h ago
    Canadian Centre for Cyber Security· 32
    Check Point security advisory (AV26-933)

    Canadian Cyber Centre relays Check Point advisory for CVE-2026-91843, a stack overflow in the login process of Security Management and Log Servers.

  8. · 5h ago
    SecurityWeek· 60
    Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

    Check Point fixes critical unauthenticated RCE CVE-2026-91843 in Security Management; Tanium and Kaspersky also patch product vulnerabilities.

  9. · 5h ago
    Security Affairs· 65
    Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution

    Check Point patched CVE-2026-91843 (CVSS 9.8), a pre-authentication root RCE in Security Management and Log Servers; no exploitation observed.

  10. · 3h ago
    BleepingComputer· 80
    New Check Point flaw lets hackers execute code with root privileges

    Check Point patched CVE-2026-91843, a stack-based buffer overflow in Security Management Server logins enabling unauthenticated root remote code execution.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-16232
Authentication Bypass in Check Point SmartConsole Grants Full Admin Access

Check Point SmartConsole, the administrative client used to manage Quantum Security Management and Multi-Domain Security Management, contains an authentication bypass (CWE-287) in its login process that allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. Exploitation is possible when the Management Server IP address is reachable from the internet and the configuration does not restrict Trusted Clients. A successful attacker can modify security policies and security configurations, effectively taking control of firewall management. Any organization running an internet-exposed Check Point management server without Trusted Client restrictions is affected, though Check Point reports exploitation has impacted only a very small number of customers. The flaw was added to CISA's KEV on 2026-07-22, is actively exploited, and press reports indicate public proof-of-concept code has been released.

Do: Apply the fix released in Check Point's advisory for CVE-2026-16232 by updating SmartConsole and the associated Quantum/MDS management software; no fixed version numbers were provided in this data, so confirm them against the vendor bulletin. As an interim mitigation, restrict internet access to the Management Server IP address and configure Trusted Clients so SmartConsole connections are accepted only from known administrator addresses. Review management logs for unexpected logins, unauthenticated token issuance, or unfamiliar administrator sessions, and complete remediation per CISA BOD 26-04 given the KEV listing.

9.372% KEV
  • Check Point SmartConsole
  • Check Point Quantum Security Management
  • Check Point Multi-Domain Security Management
largeplausibly tens of thousands of Check Point management deployments, though the vulnerable subset is only those with an internet-exposed Management Server and no…
CVE-2026-50751
Unauthenticated IKEv1 VPN Auth Bypass in Check Point Security Gateways

Check Point has disclosed CVE-2026-50751, a critical (CVSS 9.3) improper authentication flaw (CWE-287) in the certificate validation logic for Remote Access and Mobile Access VPN when the deprecated IKEv1 key exchange is used. An unauthenticated remote attacker can exploit this logic flow weakness during IKEv1 negotiation to bypass user authentication entirely. Successful exploitation lets the attacker establish a remote access VPN connection without a valid user password, gaining access to the organization's internal network resources (high confidentiality impact per the CVSS score). Any organization running a Check Point Security Gateway on Gaia OS or Gaia Embedded with IKEv1-based Remote Access/Mobile Access configured is affected; specific affected and fixed versions are in Check Point's advisory. The flaw is being exploited in the wild — it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-08 with known ransomware use and an EPSS of 83.8% — and it was disclosed alongside other critical Check Point VPN certificate flaws per recent headlines.

Do: Upgrade affected Security Gateways to the fixed releases identified in Check Point's advisory (version numbers are not specified in the source data), prioritizing internet-facing VPN gateways; as an interim mitigation, move Remote Access/Mobile Access clients to IKEv2 or disable IKEv1. Review VPN authentication logs for sessions established without valid credentials, given known in-the-wild and ransomware exploitation. Federal agencies must apply mitigations per BOD 22-01, and defenders should beware of fake 'public PoC' repositories spreading malware (ChocoPoC RAT), since no legitimate public PoC is known.

9.384% KEV ransomware PoC
  • Check Point Security Gateway (Gaia OS)
  • Check Point Security Gateway (Gaia Embedded)
massplausibly on the order of 100,000+ internet-exposed Check Point gateways, with the IKEv1-affected subset likely tens of thousands of sites (estimate)
CVE-2026-85102
Unauthenticated RCE in Check Point Quantum Security Gateway via certificate flaw

CVE-2026-85102 is an improper certificate trust-validation flaw (CWE-295) in the VPN negotiation code of Check Point Quantum Security Gateways. An unauthenticated remote attacker who can reach the gateway's VPN service can trigger the flaw during VPN negotiation, where certificates involved in the exchange are not properly validated, and achieve code execution on the gateway. Successful exploitation yields arbitrary code execution on the gateway with high impact on confidentiality, integrity, and availability (CVSS 9.8), amounting to full compromise of the security gateway. The affected population is organizations running Quantum Security Gateways with VPN services reachable from untrusted networks. As of the available reporting there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation is confirmed; the issue was disclosed alongside a second, similarly rated (9.8) Check Point VPN certificate-validation RCE flaw.

Do: Upgrade Quantum Security Gateways to the fixed versions listed in Check Point's advisory (AV26-902) as soon as they are published, prioritizing internet-facing VPN gateways. Until patched, restrict exposure of VPN negotiation endpoints to trusted networks and monitor VPN services for anomalous handshake activity. Inventory which gateways in your estate expose VPN services publicly and treat those as the highest-priority targets.

9.8
  • Check Point Quantum Security Gateway (VPN negotiation functionality)
largetens of thousands of internet-exposed Quantum VPN gateways (est.); total Check Point installed base plausibly in the hundreds of thousands of appliances/sites
CVE-2026-85103
Unauthenticated RCE in Check Point Quantum VPN Certificate ASN.1 Decoding

CVE-2026-85103 is a heap-based buffer overflow (CWE-122) in the ASN.1 certificate-decoding code used by Check Point's VPN implementation, rated 9.8 Critical with a network-exploitable, unauthenticated, low-complexity vector. An unauthenticated remote attacker can trigger the flaw by sending crafted certificate data that the VPN service parses during connection handling, causing heap corruption that allows arbitrary code execution on the target system. Successful exploitation grants the attacker code execution with high confidentiality, integrity, and availability impact, which on security gateways and management servers could mean control of the security infrastructure itself. Any organization running Check Point Quantum Security Management or Quantum Security Gateway systems that process VPN certificate traffic is potentially affected, and the advisory set indicates this flaw was disclosed alongside a second, similarly rated 9.8 VPN certificate vulnerability (Check Point advisory AV26-902). There is no evidence of exploitation so far: the flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known.

Do: Patch promptly: because this is an unauthenticated, network-reachable 9.8-rated RCE in the VPN path, upgrade Quantum Security Management and Quantum Security Gateway deployments per Check Point's advisory (referenced as AV26-902), and check your current software versions against the affected/fixed ranges listed there, which are not specified in the data available here. Until patched, restrict access to exposed VPN and management interfaces to trusted source IPs where possible and monitor VPN endpoints for anomalous connection or crash behavior. Inventory all Quantum appliances and management servers, since the flaw affects both product lines and was disclosed together with a second 9.8 VPN certificate flaw.

9.8
  • Check Point Quantum Security Management
  • Check Point Quantum Security Gateway
largelikely tens of thousands (order of magnitude 10k–100k) of deployed Quantum gateways/management servers, of which a substantial share expose VPN endpoints to…
CVE-2026-91843
Unauthenticated stack overflow gives root RCE in Check Point login process

CVE-2026-91843 is a stack-based buffer overflow (CWE-121) in the unauthenticated login process of a Check Point product, as Check Point Software ([email protected]) is the assigning CNA and its CVE scope covers Check Point products. An attacker can trigger the flaw remotely by sending crafted input to the login interface before authenticating, with no user interaction or credentials required. Successful exploitation allows arbitrary code execution with root privileges, the highest level of control on the affected system. The vulnerability is rated 9.8 Critical (AV:N/AC:L/PR:N/UI:N, all impacts high), reflecting trivial network exploitability. No public proof-of-concept or confirmed in-the-wild exploitation is known at this time, and the source data does not name the specific product line or affected version ranges.

Do: Monitor Check Point's official advisory channels for the affected product/version list and patch release, and upgrade as soon as fixed versions are published. In the interim, restrict the login/management interface of Check Point appliances to trusted management networks and remove any direct internet exposure, and review perimeter logs for anomalous pre-authentication traffic against that interface.

9.8
  • Check Point