logo

Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks

ID: 8fc6a1bf-6abe-5fbf-9e18-a3789d4afdb1

STIX ID: report--8fc6a1bf-6abe-5fbf-9e18-a3789d4afdb1

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-09-10

Date Updated: 2026-09-11

Author: Guru Baran

...
...

**Check Point disclosed and patched two critical VPN vulnerabilities (CVE-2026-85102 — improper certificate trust validation; CVE-2026-85103 — ASN.1 heap-based buffer overflow) rated CVSS 9.8 that can enable unauthenticated remote code execution across Security Gateway, Security Management, and Spark Firewall deployments; no active exploitation or public PoC has been observed, and administrators are urged to apply Live Patch or the specified Jumbo Hotfix Accumulators immediately, with limited mitigations available for Site-to-Site VPNs.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.