Unauthenticated RCE via VPN certificate handling in Check Point products
CVSS 9.8 critical: unauthenticated RCE via VPN certificate handling in Check Point firewall and management products. Check Point released patches September 2026.
- Vendor
- Check Point
- Product
- Check Point firewall and management products
- CVSS
- 9.8
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
An unauthenticated remote code execution vulnerability in Check Point’s VPN certificate processing logic. CVSS 9.8 critical. An attacker with network access to the affected interface can execute code on the device without credentials and without user interaction.
Affected products
Check Point firewall and management products that process VPN certificates. Consult Check Point’s security advisory for specific affected versions and fix builds for your product branch.
Mitigation
Apply Check Point’s patch. If immediate patching is not possible, restrict network access to management interfaces to known administrative hosts to reduce exposure.
This CVE was disclosed alongside CVE-2026-85103, a companion flaw with the same CVSS score and attack class in the same product family. Treat both as a single remediation priority.
For full coverage, see Check Point Patches Two CVSS 9.8 VPN RCE Flaws.
