news.mlab.sh
Back to the feed
vulnerability

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

CriticalCVSS 9.8
Summary

Check Point has disclosed two critical vulnerabilities (CVE-2026-85102 and CVE-2026-85103) in its Security Gateways and Security Management Server, potentially allowing unauthenticated remote code execution. These flaws stem from certificate handling and heap buffer overflows, respectively. While Check Point has released patches via Live Patch and Jumbo Hotfix, some customers are experiencing delays in receiving the updates, and the company hasn't yet provided specific details about affected versions or potential exploitation activity.

Check Point has announced two critical vulnerabilities impacting its firewall and management products, potentially allowing unauthenticated remote code execution. The flaws, identified as CVE-2026-85102 and CVE-2026-85103, relate to certificate handling and heap buffer overflows, respectively. The first vulnerability, CVE-2026-85102, is a failure to properly validate certificate trust during VPN negotiation, allowing an unauthenticated remote attacker to run code on the Security Gateway. The second, CVE-2026-85103, is a heap-based buffer overflow that occurs while the product decodes the ASN.1 structure of a VPN certificate, potentially leading to code execution on Quantum Security Management and Quantum Security Gateway systems.

Both vulnerabilities carry a CVSS score of 9.8, indicating a high severity. Check Point released patches through its Live Patch system, which automatically applies updates to customers using it, and via Jumbo Hotfix installations for specific versions. However, some customers are experiencing delays in receiving these updates, with several reporting that their gateways remain on older versions (Take 18 or 17) as of the announcement date.

The Canadian Center for Cyber Security published an advisory on the same day, listing a broader set of affected products, but without specifying versions. These include Security Gateway, Security Management Server, and Spark Firewall, Check Point’s small-business line. Notably, Spark appears twice – once for VPN deployments and once without.

Check Point has not yet published indicators of compromise for either vulnerability, and a staff member indicated that indicators of compromise only apply to existing exploits. Customers have also expressed difficulty accessing the provided advisory links, with some reporting failures across multiple browsers, despite the Live Patch link working. The company has acknowledged these issues and confirmed that the links are functioning.

Furthermore, the company has not provided specific details about affected versions, builds containing the fix, or the precise conditions required to trigger the vulnerabilities. A customer asked if disabling VPN-related rules would mitigate the risk, but received no clear guidance. The lack of information regarding potential exploitation and remediation steps leaves customers with limited ability to fully assess and address the risks.

Read the full article at The Hacker News