Check Point Patches Critical VPN Vulnerabilities
PatchCheck Point Security GatewayCheck Point Spark FirewallOur summary
Check Point has deployed security updates to address two critical vulnerabilities, identified as CVE-2026-85102 and CVE-2026-85103, within its VPN infrastructure. These defects, rated with a CVSS score of 9.8, allow attackers to achieve remote code execution without prior authentication by manipulating certificate data or triggering a heap overflow during ASN.1 decoding. The issues impact the Check Point Security Gateway, Check Point Spark Firewall, and Check Point Security Management Server across versions R82.10, R82, and R81.20. While the vendor has indicated there is no current evidence of wild exploitation, administrators should apply the latest Jumbo hotfixes or enable LivePatch immediately to secure their environments.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.