Check Point Identifies Critical 9.8 CVSS Vulnerabilities in VPN Certificate Handling for Remote Code Execution
Check Point identified two critical vulnerabilities (CVE-2026-85102 and CVE-2026-85103) with CVSS scores of 9.8, enabling unauthenticated remote code execution through flawed VPN certificate handling in Security Gateways and Management Servers. Patches were released, but some customers face mitigation challenges and delayed remediation updates.
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described.
One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security
*** END OF TRANSMISSION ***