Source context: this article examines information published by the source on September 10, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.
What the vulnerability is
Two critical vulnerabilities have been identified in Check Point products that could allow an unauthenticated remote attacker to execute arbitrary code on affected appliances.
- CVE-2026-85102: An improper certificate-data validation vulnerability occurring during the VPN negotiation flow. This specifically affects the Security Gateway.
- CVE-2026-85103: A heap overflow vulnerability within the VPN certificate ASN.1 decoding flow. This affects both the Security Gateway and the Security Management Server.
Exposure and applicability
These vulnerabilities are applicable only to deployments configured to use either Remote Access VPN or Site-to-Site VPN. If these features are not enabled, the attack vector is not present.
The affected products and versions include:
* Check Point Security Gateway: R80, R80.10, R80.20, R80.30, R80.40 (EOS), R81, R81.10 (EOS), R81.10.X, R81.20, R82, R82.00.X, and R82.10.
* Check Point Security Management Server: All versions listed above.
* Check Point Spark Firewall (Centrally and Locally Managed): All versions listed above.
Remediation priorities
Our analysis suggests prioritizing remediation based on the asset’s position in the network architecture. Because these vulnerabilities allow unauthenticated remote access, internet-facing perimeter appliances represent the highest risk and should be patched first.
Infrastructure owners should prioritize as follows:
1. External Gateways: Apply vendor hotfixes to all internet-facing Security Gateways utilizing VPN services.
2. Management Servers: Address CVE-2026-85103 on Security Management Servers, as these hold critical orchestration data.
3. Internal Segments: Patch internal Spark Firewalls and gateways that facilitate Site-to-Site VPNs between trusted zones.
How to validate remediation
To ensure exposure has been reduced, defenders must move beyond simple version checks. While confirming the installation of the vendor hotfix is the first step, validation should include:
* Configuration Audit: Verify which appliances have Remote Access or Site-to-Site VPN enabled to confirm the scope of the affected surface.
* Deployment Verification: Confirm that the hotfix is active across all nodes in a cluster, as partial patching may leave redundant gateways exposed.
Limits and open questions
Applying a hotfix reduces the likelihood of exploitation but does not eliminate all residual risk associated with the VPN negotiation flow. It remains unclear if there are alternative configurations or compensating controls that can mitigate these vulnerabilities without applying the hotfixes. Furthermore, because CVE-2026-85103 affects both the Gateway and the Management Server while CVE-2026-85102 is limited to the Gateway, defenders must ensure they are tracking the remediation of both distinct flaws across their specific asset inventory.
Source and editorial note
Security Advisory 2026-012 · Source date: September 10, 2026 · Retrieved September 14, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗