Skip to content
feed: live
>_0dayNews
check point

Check Point Patches Two CVSS 9.8 VPN RCE Flaws

CVE-2026-85102 and CVE-2026-85103 allow unauthenticated RCE via VPN certificate handling in Check Point firewall products. Patches are out now.

Check Point Patches Two CVSS 9.8 VPN RCE Flaws
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·1 min read

Check Point has patched two CVSS 9.8 critical vulnerabilities in its firewall and management products. Both are in how those products handle VPN certificates. Both let an unauthenticated remote attacker execute code on the affected device with no credentials and no user interaction required.

Tracked as CVE-2026-85102 and CVE-2026-85103, Check Point disclosed the flaws on September 10. The Hacker News reported the disclosures and SecurityWeek confirmed patches are available.

What’s at risk

The flaws are in the VPN certificate processing logic of Check Point’s firewall and management products. The attack path is unauthenticated and network-reachable: an attacker who can reach the affected interface gets code execution without supplying credentials.

That combination on a device that sits at or manages the network perimeter is a problem. Check Point firewall and management products handle VPN access, policy enforcement, and traffic between network segments.

What to do

Check Point has released patches for both CVEs. Consult Check Point’s security advisory via their support center for the affected product versions and fix builds for your environment. Internet-facing firewall appliances and management consoles go first.

If patching today isn’t possible: restrict management interface access to known administrative hosts only. That cuts the network-reachable attack surface. It does not fix the underlying flaw.

Context

Check Point SmartConsole CVE-2026-16232, an admin authentication bypass, was actively exploited and landed in CISA’s KEV catalog in July. A Rapid7 technical analysis and a public PoC appeared within a week of that listing.

CVE-2026-85102 and CVE-2026-85103 are not in the KEV catalog as of this writing. A pair of CVSS 9.8 unauthenticated RCEs on network edge products generally attracts attention quickly once researchers begin testing. Get the patches in before that timeline compresses further.

Related CVEs
  • [ CRITICAL ]CVE-2026-85102Unauthenticated RCE via VPN certificate handling in Check Point products
  • [ CRITICAL ]CVE-2026-85103Unauthenticated RCE via VPN certificate handling in Check Point products

Found this useful? Share it.