CHECK Point has issued emergency security updates on 9 September 2026 to fix two critical VPN flaws in the Quantum Security Gateway line. The vulnerabilities, CVE-2026-85102 and CVE-2026-85103, are rated CVSS v3.1 at 9.8 (Critical) and could allow unauthenticated remote code execution over standard network channels.
Check Point’s advisories describe CVE-2026-85102 as an improper certificate validation issue during VPN negotiation that could enable arbitrary code execution, while CVE-2026-85103 stems from a heap overflow in the VPN certificate ASN.1 decoding flow, also permitting remote code execution. Security researchers note there is no confirmed exploitation in the wild at this time.
Affected products include Security Gateway, Security Management Server, and Spark Firewall models, with releases R81.20, R82, and R82.10 impacted. Older end-of-support lines from R80 through R81.10 also contain the vulnerable code, whereas R82.20 remains unaffected. There is currently no public PoC exploit, and exploitation requires remote access via normal network channels with no prior authentication.
Check Point has rolled out fixes via its automated LivePatch service, with Jumbo Hotfix Accumulator packages available for affected release branches. For manual mitigations on Site-to-Site VPNs, administrators are advised to disable implied VPN rules and restrict UDP ports 500 and 4500 to specific peer IPs. Organisations should apply these updates promptly to protect perimeters and prevent potential takeovers of gateways.