www.cyber.gc.ca
Critical Vulnerabilities Disclosed in Check Point VPN Products
Article Content
Check Point has disclosed two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both rated 9.8 on the CVSS scale. These flaws affect the Security Gateway and Security Management Server, allowing unauthenticated remote attackers to execute arbitrary code under specific conditions. The vulnerabilities arise from improper certificate trust validation and a heap-based buffer overflow during VPN certificate decoding. Affected versions include R80, R81, and R82 with specific Jumbo Hotfix levels. Check Point began rolling out patches on September 9, 2026, and has advised customers to apply updates promptly. The Canadian Cyber Security Centre has also issued advisories regarding these vulnerabilities. No evidence of exploitation has been reported yet, but the vulnerabilities pose a significant risk to users. Organizations are urged to review the advisory and apply necessary updates.
Key Points: • Two critical vulnerabilities in Check Point VPN products disclosed, CVSS score 9.8. • CVE-2026-85102 allows remote code execution via improper certificate trust validation. • Patches were released on September 9, 2026; immediate action is recommended.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.