Check Point Patches Critical VPN Vulnerabilities
Check Point has released critical patches to address two vulnerabilities in its gateway and firewall products that could allow remote code execution without authentication. These flaws stem from improper certificate validation and a heap overflow, and while currently unexploited, they represent a significant risk.
Check Point announced the release of security updates to address two critical vulnerabilities within its gateway and firewall products that utilize VPN functionality. These vulnerabilities, tracked as CVE-2026-85102 and CVE-2026-85103, could lead to remote code execution (RCE) if exploited. CVE-2026-85102 affects Security Gateway and Check Point Spark Firewall when using Site to Site VPN or Remote Access VPN, while CVE-2026-85103 impacts the Check Point Security Management Server, Security Gateway, and Spark Firewall. The former vulnerability is caused by improper validation of certificate data during VPN negotiation, and the latter is a heap overflow in the VPN certificate ASN.1 decoding flow. Check Point recommends manually defining VPN rules for Site to Site VPN, specifically disabling implied rules and defining VPN access for UDP/500 and UDP/4500 for specific peer IP addresses. For locally managed Spark Firewall instances, the company advises applying the latest Jumbo hotfixes immediately. Customers utilizing Check Point LivePatch will receive these patches automatically. Check Point discovered these vulnerabilities internally and reports that there is currently no evidence of exploitation in the wild. This follows previous warnings regarding other zero-day vulnerabilities, including CVE-2026-16232 and CVE-2026-50751.