News

Check Point patches two critical VPN certificate flaws

Check Point SecureKnowledge sk1000117 and sk1000118 (last modified 9 September 2026) cover CVE-2026-85102 and CVE-2026-85103, both CVSS 9.8. Fixes include LivePatch Take 24 and Jumbo Hotfix R82.10 Take 44, R82 Take 126, and R81.20 Take 166. R82.20 is not affected.

Check Point patches two critical VPN certificate flaws

Check Point published two critical SecureKnowledge advisories last modified 9 September 2026: sk1000117 for CVE-2026-85102 and sk1000118 for CVE-2026-85103. Both carry a CVSS score of 9.8. Canada's Cyber Centre alert AV26-902, dated the same day, points administrators at those two pages.

These are vendor critical advisories plus a national CERT alert. They are not a CISA Known Exploited Vulnerabilities listing, and Check Point says it has no indication either flaw has been used in an attack.

CVE-2026-85102 is improper validation of certificate data during VPN negotiation. Check Point says that may let an unauthenticated remote attacker run code on the Security Gateway. It affects Security Gateway and Spark Firewall using Site-to-Site or Remote Access VPN.

CVE-2026-85103 is a heap overflow in VPN certificate ASN.1 decoding. The advisory title and the CCCS listing say that may allow remote code execution on Security Management Server, Security Gateway, and Spark. Affected branches include R81.20, R82, and R82.10, plus older end-of-support lines. R82.20 is listed as not affected.

The urgent LivePatch package is Take 24 for R82.10, R82, and R81.20. Permanent Jumbo Hotfix floors named with those advisories are R82.10 Take 44, R82 Take 126, and R81.20 Take 166. Spark fixes are R82.00.10 Build 2325 and R81.10.17 Build 4968.

For Site-to-Site VPN, Check Point's mitigation is to disable implied VPN rules and manually define UDP/500 and UDP/4500 for specific peer IP addresses. That workaround does not apply to locally managed Spark.

Check Point says remote code execution requires specific conditions it has not fully spelled out in the public summaries. The Hacker News (Swati Khandelwal, 10 September 2026), reading the customer community thread, reported R81.10 operators still without LivePatch or Jumbo, and some automatic LivePatch rollouts still sitting on Take 17 or Take 18.

Related edge-device and management-plane notes include WatchGuard Firebox RCE now marked for ransomware use, Cisco Secure FMC under active attack, and IDScan's 150 million-plus license incident. Lab-side incident writeups this week include Anthropic's fourth Claude cyber eval breakout.

If you run R81.20, R82, or R82.10 with VPN or management in play, apply LivePatch Take 24 or the matching Jumbo Take today and confirm cplp list shows both CVEs. If the box is already on R82.20, skip the emergency take. If the box is still on R81.10, use the Site-to-Site UDP/500 and UDP/4500 peer-IP workaround until a take ships for that branch, and do not wait for a KEV row that is not on the page.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free