Unauthenticated RCE via VPN certificate handling in Check Point products
CVSS 9.8 critical: companion to CVE-2026-85102, a second unauthenticated RCE in Check Point's VPN certificate handling. Patched September 2026.
- Vendor
- Check Point
- Product
- Check Point firewall and management products
- CVSS
- 9.8
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
An unauthenticated remote code execution vulnerability in Check Point’s VPN certificate processing logic, disclosed alongside CVE-2026-85102. CVSS 9.8 critical. An attacker with network access can execute code on affected devices without credentials and without user interaction.
Affected products
Check Point firewall and management products that process VPN certificates. Consult Check Point’s security advisory for specific affected versions and fix builds for your product branch.
Mitigation
Apply Check Point’s patch. If immediate patching is not possible, restrict management interface access to known administrative hosts.
Both CVE-2026-85103 and CVE-2026-85102 were patched in the same September 2026 advisory. Treat them as a single remediation task.
For full coverage, see Check Point Patches Two CVSS 9.8 VPN RCE Flaws.
