Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
Check Point has patched two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that could let an unauthenticated remote attacker execute code on Security Gateway and Security Management systems under specific conditions. The company says it found the issues internally, has seen no exploitation, and is rolling out fixes through Live Patch and Jumbo Hotfix updates. #CheckPoint #CVE-2026-85102 #CVE-2026-85103 #QuantumSecurityGateway #QuantumSecurityManagement

Keypoints

  • Check Point patched two critical VPN certificate vulnerabilities.
  • CVE-2026-85102 affects Security Gateways during VPN negotiation.
  • CVE-2026-85103 is a heap-based buffer overflow in VPN certificate decoding.
  • Both flaws are rated CVSS 9.8 and may allow remote code execution.
  • Customers can use Live Patch or the latest Jumbo Hotfix to remediate.

Read More: https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html