NewsTradingSentimentCalendarCommunityBriefing
Tech

Check Point patches critical VPN certificate flaws

By Tech Desk · 2026-09-10 · 3 min read
A digital padlock with a keyhole, symbolizing network security and access control.
Illustration: Tradingbird

Check Point has released urgent fixes for two high-severity vulnerabilities in its firewall and management software that could allow remote attackers to execute code without authentication.

Check Point has patched two critical security flaws in its firewall and management products that could allow an unauthenticated remote attacker to run code on affected systems. The company disclosed the issues on September 9 and began delivering fixes immediately, stating that it identified the vulnerabilities internally and has no evidence of active exploitation. Both flaws are rated 9.8 on the Common Vulnerability Scoring System, indicating a severe risk to network integrity.

The vulnerabilities affect how the software handles VPN certificates, a core component for secure remote access. One flaw involves a failure to properly validate certificate trust during the connection process. The second is a memory corruption issue that occurs while decoding certificate data. While Check Point notes these attacks require specific conditions, the company has not detailed what those conditions are, leaving administrators with limited guidance on exposure.

Technical details of the flaws

The first vulnerability, tracked as CVE-2026-85102, is a trust validation error. An attacker could potentially bypass security checks during the initial VPN handshake, leading to remote code execution on the Security Gateway. The second vulnerability, CVE-2026-85103, is a heap-based buffer overflow that triggers when the system processes the ASN.1 structure of a VPN certificate. This flaw affects both the Security Gateway and the Security Management Server, the central console used to configure the network. The complexity of these internal processes means that even minor errors in data handling can have significant security consequences.

According to The Hacker News, the affected versions include R82.10, R82, and R81.20, specifically those running older Jumbo Hotfix levels. The Canadian Center for Cyber Security also issued an advisory listing a broader range of products, including the Spark Firewall line. However, the official records do not specify which exact versions contain the fix, creating some ambiguity for users trying to determine their status. This lack of clarity is a common trade-off in rapid patching, where immediate security needs can sometimes outpace detailed public documentation.

Challenges in applying the fix

Check Point offered two methods for applying the patch: automatic updates via Live Patch and manual installation of Jumbo Hotfixes. However, customer reports indicate significant friction in this process. Several users stated that the automatic rollout had not reached their systems, with some gateways remaining on outdated update levels days after the announcement. Others reported that download links provided in the advisories were broken, forcing them to seek alternative sources for the fix. This delay creates a window of vulnerability where systems remain exposed despite the availability of a solution.

For organizations running older software branches like R81.10, the situation is more complex. Some users reported that no automatic patch or hotfix was available for their specific version, leaving them with only mitigation steps. Check Point recommended disabling certain implied rules for VPN, but customers described this guidance as vague and difficult to implement without risking disruption to remote access. The lack of specific configuration instructions in the public thread has left many administrators uncertain about the safest path forward, highlighting a gap between security recommendations and practical application.

Implications for network security

The severity of these flaws underscores the critical role of certificate management in network defense. Even when the VPN blade is technically disabled, Check Point staff indicated that the vulnerability could still be triggered if VPN certificates are present in the environment. This suggests that simply turning off a feature is not a complete defense, as the underlying code paths for certificate processing remain active. Organizations must ensure that all certificates are properly managed and that systems are updated to the latest security levels to close these gaps.

The incident serves as a reminder that high-severity vulnerabilities in widely deployed security appliances can have far-reaching impacts. While Check Point acted quickly to disclose and patch the issues, the mixed feedback from users regarding patch availability and clarity of guidance suggests that the transition to a secure state is not instantaneous. Administrators are advised to verify their patch levels and review their certificate configurations to ensure they are not left exposed to potential remote attacks.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories