CHECK Point has released patches for two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, in its VPN gateway and firewall products, with a CVSS score of 9.8. These vulnerabilities allow for remote code execution without authentication, affecting the Security Gateway and Check Point Spark Firewall. Users are advised to define VPN rules manually as a mitigation measure, particularly for Site to Site VPN. The company confirms no evidence of these vulnerabilities being exploited in the wild. Security updates apply to versions R82.10, R82, and R81.20.
Check Point Patches Critical VPN Vulnerabilities
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Check Point Patches Critical VPN Vulnerabilities
www.securityweek.com
-
Check Point Fixes Critical VPN Flaws Enabling Unauthenticated Code Execution
thehackernews.com
-
Check Point Patches Critical VPN Flaws Enabling Remote Code Execution
securityonline.info