Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

September 11, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Organizations using Check Point Quantum Security Gateways and Management Servers
Incident: Disclosure of two critical RCE vulnerabilities (CVE-2026-85102 and CVE-2026-85103) in Check Point VPN certificate handling.
Impact: Potential full system compromise and unauthenticated remote code execution on network security appliances.
Attacker: Unidentified threat actors
Analysis: The vulnerabilities stem from improper certificate trust validation and a heap-based buffer overflow during ASN.1 decoding. If exploited, an attacker could gain full control over security gateways and management servers. While Check Point reports no known exploitation in the wild, the high severity and accessibility make them prime targets for threat actors.
Recommendations: Immediately apply the latest Jumbo Hotfix or enable Check Point Live Patch.; Review security gateway logs for unusual VPN negotiation patterns.; Verify current software versions against affected R81.20, R82, and R82.10 branches.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *