Skip to content
Cyber Security News on X: "⚠️ Critical Check Point VPN Vulnerabilities Enable Remote ...

Cyber Security News on X: "⚠️ Critical Check Point VPN Vulnerabilities Enable Remote ...

X September 10, 2026

Cyber Security News on X: "⚠️ Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks

Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score of 9.8 and both capable of allowing unauthenticated remote code execution under specific conditions.

CVE-2026-85102 is rooted in improper certificate trust validation during VPN negotiation. CVE-2026-85103, by contrast, is a heap-based buffer overflow (CWE-122) that occurs while the product parses the ASN.1 structure of a VPN certificate.

The vulnerabilities affect Check Point Security Gateway, Security Management Server, and Spark Firewall deployments across multiple release branches.

⚠️ Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks

Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score of 9.8 and both capable of allowing unauthenticated remote code execution under specific conditions.

CVE-2026-85102 is rooted in improper certificate trust validation during VPN negotiation. CVE-2026-85103, by contrast, is a heap-based buffer overflow (CWE-122) that occurs while the product parses the ASN.1 structure of a VPN certificate.

The vulnerabilities affect Check Point Security Gateway, Security Management Server, and Spark Firewall deployments across multiple release branches.

⚠️ Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks

Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score of 9.8 and both capable of allowing unauthenticated remote code execution under specific conditions.

CVE-2026-85102 is rooted in improper certificate trust validation during VPN negotiation. CVE-2026-85103, by contrast, is a heap-based buffer overflow (CWE-122) that occurs while the product parses the ASN.1 structure of a VPN certificate.

The vulnerabilities affect Check Point Security Gateway, Security Management Server, and Spark Firewall deployments across multiple release branches.

Edge VPN at CVSS 10 is patch-now, not sprint. Internet-facing appliances are the blast radius. Are you treating VPN appliances like crown-jewel assets or just "network gear"?