Search/Check Point Patches Critical VPN Vulnerabilities
Story

Check Point Patches Critical VPN Vulnerabilities

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. Although no public proof-of-concept (PoC) exploit has been reported, the agency is urging organizations to install the security updates addressing the two issues as soon as possible. “The NCSC assesses the likelihood of exploitation and the potential impact as high and expects exploitation attempts to occur soon,” the NCSC warns. Check Point VPN is an enterprise solution that allows remote employees to securely connect to their company's internal network via encrypted connections. On September 9, Check Point issued fixes for the flaws along with separate security advisories describing them: sk1000117 and sk1000118.…

CVEs
2
Highest CVSS
9.8
In KEV
0
Sources
3
Connections
6 relationships
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. Although no public proof-of-concept (PoC) exploit has been reported, the agency is urging organizations to install the security updates addressing the two issues as soon as possible. “The NCSC assesses the likelihood of exploitation and the potential impact as high and expects exploitation attempts to occur soon,” the NCSC warns. Check Point VPN is an enterprise solution that allows remote employees to securely connect to their company's internal network via encrypted connections. On September 9, Check Point issued fixes for the flaws along with separate security advisories describing them: sk1000117 and sk1000118. CVE-2026-85102 is an improper validation of certificate data during VPN negotiation that a remote attacker could exploit to execute arbitrary code on a Security Gateway. CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder that could allow remote code execution on Security Gateways and Security Management Servers. Affected releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, along with the end-of-support (EoS) versions R80 through R80.40, R81, and R81.10. Both flaws are fixed by Check Point LivePatch Take 24 for R81.20, R82, and R82.10, while fixes are also included in the following versions: R82.10 Jumbo Hotfix Accumulator Take 44 or later R82 Jumbo Hotfix Accumulator Take 126 or later R81.20 Jumbo Hotfix Accumulator Take 166 or later Spark R82.00.10 Build 2325 or later Spark R81.10.17 Build 4968 or later Check Point VPN version R82.20 is not affected by either flaw. NCSC warned that exploitation of the flaws could allow an attacker to take full control of a system, view or modify confidential data, and disrupt operations. The organization urges system administrators to apply the security updates as soon as possible. At the same time, for those using the ‘Site-to-Site VPN’ component, the advice is to modify VPN rules to limit access to specific, trusted IP addresses. According to a post in Check Point’s community forums, users of Check Point Live Patch (CPLP) should have received all available protections for the two flaws since September 9, and those fixes should apply even without a server reboot. CPLP users should check if they are protected by this automatic mitigation, as it is not available for versions other than R82.10, R82, and R81.20 and doesn’t support all configurations. Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat
bleepingcomputer.comSep 12, 2026extracted
Check Point Patches Critical VPN Vulnerabilities
Cybersecurity firm Check Point this week announced patches for two critical-severity vulnerabilities in its gateway and firewall products using VPN functionality. Tracked as CVE-2026-85102 and CVE-2026-85103 (CVSS score of 9.8), both security defects could be exploited without authentication for remote code execution (RCE), Check Point warns. The former is described as an improper validation of certificate data during VPN negotiation, while the latter is a heap overflow in the VPN certificate ASN.1 decoding flow. CVE-2026-85102, the company says, affects Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN. CVE-2026-85103 impacts the Check Point Security Management Server, Security Gateway, and Spark Firewall. Security updates have been released for versions R82.10, R82, and R81.20 of all products. As a mitigation, Check Point recommends manually defining VPN rules. “For Site to Site VPN, disable implied rules for VPN and manually define VPN access for UDP/500 and UDP/4500 for the specific peer IP addresses,” Check Point recommends. The company also notes that the mitigation does not apply to locally managed Spark Firewall instances. Users with locally managed instances are advised to apply the latest Jumbo hotfixes as soon as possible. Customers with Check Point LivePatch enabled will receive the patches automatically. Check Point says it discovered both vulnerabilities internally and that there is no evidence they have been exploited in the wild. This summer the cybersecurity firm warned customers about the exploitation of two zero-day vulnerabilities, including CVE-2026-16232 and CVE-2026-50751. Related: PaperCut Flaws Exploited in AI-Powered Attacks Related: Critical NetScaler Vulnerability Exploited in Attacks Related: MikroTik Patches Critical Flaws Chained to Hack Routers Related: N-able Patches Critical Zero-Day in N-central
securityweek.comSep 11, 2026extracted
NCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN producten
Check Point heeft 2 kritieke kwetsbaarheden verholpen. De kwetsbaarheid met kenmerk CVE-2026-85102 heeft een CVSS-score van 9,8. De kwetsbaarheid bevindt zich in het VPN-onderhandelingsproces van de Quantum Security Gateway en wordt veroorzaakt door onjuiste validatie van certificaatvertrouwen. Hierdoor kan een niet-geauthenticeerde externe aanvaller authenticatiecontroles omzeilen en willekeurige code uitvoeren op de Security Gateway. Exploitatie vindt plaats tijdens de VPN-onderhandeling, waarbij certificaatgegevens onvoldoende worden gevalideerd. De kwetsbaarheid geldt voor Security Gateway en Check Point Spark Firewall wanneer Site-to-Site VPN of Remote Access VPN wordt gebruikt. Voor Site-to-Site VPN adviseert Check Point om implied rules for VPN uit te schakelen en VPN-toegang voor UDP/500 en UDP/4500 alleen expliciet toe te staan voor de specifieke peer-IP-adressen. Deze mitigatie is niet van toepassing op lokaal beheerde Spark Firewalls. De kwetsbaarheid met kenmerk CVE-2026-85103 heeft een CVSS-score van 9,8. Het betreft een heap-based buffer overflow in de ASN.1-decoding van VPN-certificaten, veroorzaakt door onjuiste verwerking van ASN.1-datastructuren tijdens de certificaatverwerking. Een niet-geauthenticeerde externe aanvaller kan deze kwetsbaarheid misbruiken om willekeurige code uit te voeren op het getroffen systeem. De kwetsbaarheid bevindt zich in een component die onderdeel is van de VPN-infrastructuur en kan bij succesvolle exploitatie de vertrouwelijkheid, integriteit en beschikbaarheid van het getroffen systeem beïnvloeden. Het NCSC verwacht dat op korte termijn pogingen tot grootschalig misbruik zullen plaatsvinden en roept organisaties op de advisory van Check Point met spoed op te volgen.
advisories.ncsc.nlSep 10, 2026extracted
Related Stories
1
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. Tracked as CVE-2026-91843, this flaw stems from a stack-based buffer overflow weakness in the login process for Security Management Server instances, which manage Security Gateways (firewalls) and monitor network security events. The security issue also affects the company's Log Server, a dedicated server that collects and stores logs generated by Check Point firewalls. Successful exploitation lets threat actors without privileges gain root remote code execution in low-complexity attacks that don't require user interaction. Check Point also provided temporary mitigation measures for customers who can't deploy the latest LivePatch, including hardening vulnerable systems against attacks and limiting access to trusted IP addresses/subnets by editing the entries under Manage & Settings > Permissions & Administrators > Trusted Clients in the SmartConsole dashboard. While the company has not yet flagged this security flaw as actively exploited, it said security teams can identify CVE-2026-91843 attacks by looking for "Administrator failed to log in: Username too long" alerts in the Audit and Admin login logs. Last week, it patched another critical remote code execution flaw (CVE-2026-85103) stemming from a heap overflow in the VPN certificate ASN.1 decoding flow that affects Check Point firewalls and management systems. "All Security Management Server deployments are vulnerable, regardless of configuration," Check Point warned. "The vulnerability is not dependent on any specific management configuration. The management is vulnerable even when VPN in not in use or configured." The same day, it patched a second critical flaw (CVE-2026-85102) that lets unauthenticated hackers bypass authentication and execute code remotely on vulnerable firewalls. Although these vulnerabilities are not yet exploited in the wild, Check Point flagged other flaws as actively exploited in recent months. The first, an authentication bypass (CVE-2026-50751) zero-day, was abused by a Qilin ransomware affiliate since June, while a second authentication bypass zero-day (CVE-2026-16232) has been exploited since at least July to authenticate with administrator privileges to SmartConsole admin panels. More recently, the Dutch National Cyber Security Centre (NCSC-NL) warned organizations to prioritize patching two critical Check Point VPN flaws tracked as CVE-2026-85102 and CVE-2026-85103 because it "expects exploitation attempts to occur soon." Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat
3 shared
Sep 18, 2026