Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
ID: 45a3156b-0dea-5c1d-8b9c-a3516dbfa764
STIX ID: report--45a3156b-0dea-5c1d-8b9c-a3516dbfa764
Feed Name: The Hacker News
Check Point disclosed and patched two critical VPN certificate–related vulnerabilities (CVE-2026-85102 and CVE-2026-85103, both CVSS 9.8) affecting Quantum Security Gateways and Security Management Server branches (R81.20, R82, R82.10). Both allow unauthenticated remote code execution under unspecified conditions; fixes are being rolled out via Live Patch and Jumbo Hotfixes but some customers reported delayed or unavailable updates and unclear mitigation guidance, and Check Point reports no evidence of active exploitation or published IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
