Check Point Patches Critical VPN Vulnerabilities
Cybersecurity firm Check Point this week announced patches for two critical-severity vulnerabilities in its gateway and firewall products using VPN functionality.
Tracked as CVE-2026-85102 and CVE-2026-85103 (CVSS score of 9.8), both security defects could be exploited without authentication for remote code execution (RCE), Check Point warns.
The former is described as an improper validation of certificate data during VPN negotiation, while the latter is a heap overflow in the VPN certificate ASN.1 decoding flow.
CVE-2026-85102, the company says, affects Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN.
CVE-2026-85103 impacts the Check Point Security Management Server, Security Gateway, and Spark Firewall.
Security updates have been released for versions R82.10, R82, and R81.20 of all products. As a mitigation, Check Point recommends manually defining VPN rules.
Advertisement. Scroll to continue reading.
“For Site to Site VPN, disable implied rules for VPN and manually define...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE