Check Point issues urgent warning: Two critical VPN vulnerabilities threaten firewall systems
Recently, renowned cybersecurity firm Check Point urgently released patches for two extremely critical security vulnerabilities residing in its firewall products and network management systems. Carrying near-maximum risk severity scores, these vulnerabilities, if exploited, could allow hackers to gain remote control of systems without requiring any login credentials. Although there are no signs of active exploitation in the wild, this remains critical information that every system administrator needs to pay close attention to.

Check Point's two VPN vulnerabilities scored 9.8
On September 9, 2026, Check Point notified its customer community about two new vulnerabilities that the company itself discovered during the device processing of VPN certificates. Both flaws were assigned a CVSS score of 9.8 (out of 10) – a red alert level in the information security industry. They both pose a risk of Remote Code Execution (RCE). Put simply, RCE allows attackers to run malicious commands on a victim's server from thousands of kilometers away without needing to know any account username or password.
Specifically, the first vulnerability, designated CVE-2026-85102, stems from the system failing to properly validate digital certificates (used to verify connection identity) when establishing VPN connections. This vulnerability directly affects the Security Gateways product line (the company's firewall devices).
The second flaw, CVE-2026-85103, is a "buffer overflow" bug – a phenomenon occurring when the amount of data crammed into the system exceeds memory capacity. This error arises when the device attempts to decode the structure of a VPN certificate. Beyond targeting firewalls, this flaw also threatens central security management servers. Notably, a company employee confirmed that theoretically, even if an enterprise has completely disabled the VPN feature, the attack vector could still be triggered if VPN certificates remain stored in that network environment.
Which systems are at risk?
According to official advisories, affected management software versions under Check Point's Quantum branch include: R82.10, R82, and R81.20 (corresponding to specific minor updates).
However, the actual picture may be broader. An advisory from the Canadian Centre for Cyber Security released on the same day also listed the Spark Firewall series – Check Point's firewall line designed specifically for small businesses. Interestingly, Spark devices were named regardless of whether they were actively running a VPN configuration (remote access or site-to-site connections). Fortunately, as of now, the security vendor stated that it has recorded no evidence of hackers exploiting these two vulnerabilities outside laboratory environments.
Patch updates: Solution available but incomplete
To fix the issues, Check Point provided users with two options: using an automatic update system (Live Patch) or installing a manual patch (Jumbo Hotfix). However, the actual deployment process has not been smooth for everyone.
Many network administrators have voiced complaints on the vendor's community forums. Several customers running older operating system versions (such as version R81.10) found themselves in a dilemma, as no patches were available for them. The workaround suggested by the vendor – disabling certain implicit VPN connection rules – was criticized by users as overly vague, difficult to implement, and risky in terms of disrupting work for remote employees. In addition, some administrators reported that their automatic update process stalled for days, or that patch download links in the advisory documentation were broken and inaccessible.
A wake-up call from previous incidents
This incident easily recalls the turbulence Check Point experienced over the past summer. Just in June and July, the vendor had to release patches for other critical vulnerabilities in these very product lines. Even more concerning, those previous security flaws were actively exploited by hackers in real-world network environments at the time of their announcement, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to immediately add them to its list of actively exploited vulnerabilities worldwide.
Against the backdrop of increasingly automated and sophisticated cyberattacks, the emergence of critical vulnerabilities in core security equipment like firewalls is a risk that cannot be taken lightly. Organizations and enterprises using Check Point products need to quickly check their system versions, apply patches as soon as possible, or actively monitor temporary mitigation guidance from the vendor to ensure their networks remain fully secured.
Refer to: The Hacker News












Comments