Threat Intelligence

Check Point Patches Two Critical VPN Certificate Flaws Rated 9.8 Severity

The Hacker News · 10 Sept 2026
Key Takeaway Small businesses using Check Point firewalls or Spark devices should apply the available patches immediately, even if VPN features appear disabled, since certificate handling alone can expose the vulnerability.

Check Point has released fixes for two critical security flaws affecting how its firewall and management products process VPN certificates. Both vulnerabilities, disclosed to customers on September 9, could allow an attacker with no login credentials to run malicious code on affected systems, though Check Point notes this would only occur under specific, undisclosed conditions.

The first flaw, CVE-2026-85102, involves a failure to properly verify certificate trust during VPN negotiation, potentially allowing code execution on Security Gateway appliances. The second, CVE-2026-85103, is a buffer overflow triggered while the software decodes VPN certificate data, affecting both Quantum Security Management and Quantum Security Gateway products. Both flaws carry the maximum practical severity score of 9.8 out of 10. Check Point says it discovered the issues internally and has seen no evidence of active exploitation.

Affected products include several Quantum branches, as well as Security Management Server and the Spark Firewall line used by small businesses, according to a separate advisory from the Canadian Centre for Cyber Security. Notably, a Check Point staff member confirmed that even gateways with VPN functionality disabled could theoretically be at risk if VPN certificates are still present on the system, since the flaw relates to certificate processing rather than active VPN use.

Check Point VPN Security Critical Vulnerability Patch Management Network Security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.