Back to blog
CVEVPNenterprise

Check Point CVE-2026-85102 / 85103: Two 9.8 VPN Flaws with Unauthenticated RCE, Exploitation Called Imminent

Published on 2026-09-135 min readCleanIssue

> TL;DR: On September 9, 2026, Check Point fixed two critical vulnerabilities in how its firewalls and management consoles handle VPN certificates. CVE-2026-85102 (CVSS 9.8) is a failure to properly validate certificate trust during VPN negotiation, potentially enabling unauthenticated remote code execution on Security Gateways. CVE-2026-85103 (CVSS 9.8) is a heap-based buffer overflow while decoding a certificate's ASN.1 structure, affecting Quantum Security Management and Quantum Security Gateway systems. Check Point, which found both flaws internally, says it has no evidence of exploitation — but the Dutch NCSC warns exploitation is imminent. Affected versions: R82.10 (JHF Take 43 and below), R82 (Take 125 and below), R81.20 (Take 165 and below).

The mechanism: the certificate as attack surface

Both flaws trigger during certificate processing — attacker-controlled input in VPN flows. The first breaks trust validation (a malicious certificate passes as legitimate, with potential code execution on the gateway); the second corrupts memory during ASN.1 decoding (heap overflow, same outcome). Two important Check Point clarifications:

  • The defect exists even on appliances without an active VPN blade, as long as VPN certificates are present and processed — the exposure perimeter is wider than production VPNs alone.
  • The Canadian advisory widens the list to the Spark line (SMB) and the Security Management Server, without version details.
  • The vendor's context presses: in June, CVE-2026-50751 (Remote Access VPN authentication bypass) was already exploited at disclosure (KEV June 8); in July, CVE-2026-16232 (SmartConsole) was KEV'd the same day. Check Point VPN flaws have a history: they convert into access fast.

    The editorial response blind spots

    The case also offers operational lessons, reported by customers on the community forum: R81.10 branches with no patch path (mitigation only, described as too vague to apply), a progressive Live Patch rollout that had not reached all appliances days after the announcement, broken download links, and no published IoCs — logical, since no public exploit exists yet. For your teams: do not assume the fix is applied because it is available; verify the effective version on every appliance, including secondary lines (Spark, management).

    What to do

  • Apply the fix via the fastest available route: Check Point Live Patch (automatic rollout started September 9, installable on any Jumbo Hotfix level in R81.20, R82, and R82.10) or the latest Jumbo Hotfix for your branch.
  • Verify the effective version of every gateway and console — not the planned version, the actually installed one (several customers found Take 17/18 lagging by days).
  • Identify appliances on uncovered branches (R81.10) and pivot to mitigation: reduce VPN service exposure, restrict allowed sources, plan the branch migration.
  • Do not forget dormant certificates: flaw 85103 triggers on certificate processing even without active VPN — inventory certificates present on your appliances.
  • Prepare detection for the day IoCs exist: VPN negotiation failure logging, alerting on connections with malformed certificates.
  • The broader lesson

    Firewalls and VPN concentrators are the most systematically converted initial-access category of the past three years (Ivanti, Fortinet, Palo Alto, Citrix, SonicWall, and now Check Point repeatedly). The reason is structural: they are exposed by function, they process unauthenticated input (certificates, handshakes), and compromising them delivers the inside of the network. Two consequences for every organization: their patch cycle must be the shortest in the estate (hours, not weeks), and the assumption "the VPN may be compromised" must exist in the architecture — segmentation behind the gateway, MFA on internal resources, monitoring of accounts transiting through it.

    Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Related articles

    Three adjacent analyses to keep exploring the same attack surface.

    CVEMSP

    PaperCut NG/MF: Two Zero-Days Chained for Unauthenticated RCE, Incomplete Patches, and a CISA Deadline

    Flaws in the PaperCut NG and MF print management software are exploited in real attacks: an authentication bypass (CVE-2026-81578) followed by unsafe dynamic class loading (CVE-2026-82078) leads to arbitrary Java code execution without an account. Two successive emergency patches, patch bypasses already identified against the latest fully patched version, and a CISA KEV entry with a September 14, 2026 deadline.

    2026-08-31 · 7 min read
    CVESaaS

    ServiceNow: Three CVSS 10.0 Flaws Including a GraphQL Injection — Self-Hosted Instances Must Patch Themselves

    Four vulnerabilities fixed on August 27, 2026 in the ServiceNow platform, three of them rated 10.0: code injection in the GraphQL Composite Data API (CVE-2026-18885), broken access control in the configuration image upload processor (CVE-2026-18886), SQL injection via a dynamic ORDER BY (CVE-2026-74820), plus a sandbox escape (CVE-2026-6876). ServiceNow-hosted instances are already protected.

    2026-08-29 · 6 min read
    CVEenterprise

    Cisco FMC CVE-2026-20079: Three Attacker Clusters, from Web Shells to Qilin Ransomware via Sandworm

    Cisco Talos documents three clusters exploiting patched Secure Firewall Management Center flaws: CVE-2026-20079 (CVSS 10.0 auth bypass leading to root) and CVE-2026-20316 (5.3 low-privilege access as entry). Web shells and credential theft, a Cyclops Blink implant linked to Sandworm, and a full Qilin deployment through legitimate FMC tooling. KEV deadline: September 12.

    2026-09-11 · 5 min read

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit