logo

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

ID: 45a3156b-0dea-5c1d-8b9c-a3516dbfa764

STIX ID: report--45a3156b-0dea-5c1d-8b9c-a3516dbfa764

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-09-10

Date Updated: 2026-09-11

Author: [email protected] (The Hacker News)

...
...

Check Point disclosed and patched two critical VPN certificate–related vulnerabilities (CVE-2026-85102 and CVE-2026-85103, both CVSS 9.8) affecting Quantum Security Gateways and Security Management Server branches (R81.20, R82, R82.10). Both allow unauthenticated remote code execution under unspecified conditions; fixes are being rolled out via Live Patch and Jumbo Hotfixes but some customers reported delayed or unavailable updates and unclear mitigation guidance, and Check Point reports no evidence of active exploitation or published IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.