Cybersecurity firm Check Point this week announced patches for two critical-severity vulnerabilities in its gateway and firewall products using VPN functionality.
Tracked as CVE-2026-85102 and CVE-2026-85103 (CVSS score of 9.8), both security defects could be exploited without authentication for remote code execution (RCE), Check Point warns.
The former is described as an improper validation of certificate data during VPN negotiation, while the latter is a heap overflow in the VPN certificate ASN.1 decoding flow.
CVE-2026-85102, the company says, affects Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN.
CVE-2026-85103 impacts the Check Point Security Management Server, Security Gateway, and Spark Firewall.
Security updates have been released for versions R82.10, R82, and R81.20 of all products. As a mitigation, Check Point recommends manually defining VPN rules.
“For Site to Site VPN, disable implied rules for VPN and manually define VPN access for UDP/500 and UDP/4500 for the specific peer IP addresses,” Check Point recommends.
The company also notes that the mitigation does not apply to locally managed Spark Firewall instances.
Users with locally managed instances are advised to apply the latest Jumbo hotfixes as soon as possible. Customers with Check Point LivePatch enabled will receive the patches automatically.
Check Point says it discovered both vulnerabilities internally and that there is no evidence they have been exploited in the wild.
This summer the cybersecurity firm warned customers about the exploitation of two zero-day vulnerabilities, including CVE-2026-16232 and CVE-2026-50751.
Related: PaperCut Flaws Exploited in AI-Powered Attacks
Related: Critical NetScaler Vulnerability Exploited in Attacks
Related: MikroTik Patches Critical Flaws Chained to Hack Routers


