TWO critical VPN certificate flaws in Check Point’s firewall and management products have been fixed. The company disclosed two CVEs—CVE-2026-85102 and CVE-2026-85103—both rated 9.8 on the CVSS scale. CVE-2026-85102 arises from improper validation of certificate trust during VPN negotiation, potentially allowing an unauthenticated remote attacker to run code on the Security Gateway.
CVE-2026-85103 is a heap-based buffer overflow triggered while decoding the ASN.1 structure of a VPN certificate, with the risk of code execution on Quantum Security Management and Quantum Security Gateway systems. Check Point says there is no confirmed exploitation at this time.
The same affected product list covers three Quantum branches: R82.10 (Jumbo Hotfix Take 43 or below), R82 (Jumbo Hotfix Take 125 or below), and R81.20 (Jumbo Hotfix Take 165 or below). The vulnerabilities affect both Security Gateways and the Security Management Server, with a broader advisory from Canada’s Cyber Security Centre noting Spark Firewall and smaller business lines too.
Patches were issued on 9 September 2026 via Live Patch and Jumbo Hotfixes, with Live Patch described as protecting customers automatically as rollout begins. Some users on older branches (e.g., R81.10) reported limited or delayed access to fixes, highlighting ongoing patching hesitations. Check Point stated there is no evidence of external exploitation and that indicators of compromise would apply only to already-known exploits. The firm’s advisories sk1000117 and sk1000118 remain the primary sources for affected products, mitigation, and remediation steps.