Threat Advisory

Check Point VPN Flaws Allow Unauthenticated Remote Code Execution

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting checkpoint Quantum Security Gateway versions. These Check Point VPN vulnerabilities affect Security Gateway, Security Management Server, and Spark Firewall models allowing unauthenticated remote code execution. The affected versions include R81.20, R82, R82.10, and older end-of-support versions from R80 through R81.10. These critical-severity flaws pose a severe risk to enterprise operations.

CVE-2026-85102 (CVSS 9.8 — Critical): Improper certificate validation during session establishment may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting checkpoint Quantum Security Gateway versions. These Check Point VPN vulnerabilities affect Security Gateway, Security Management Server, and Spark Firewall models allowing unauthenticated remote code execution. The affected versions include R81.20, R82, R82.10, and older end-of-support versions from R80 through R81.10. These critical-severity flaws pose a severe risk to enterprise operations.

CVE-2026-85102 (CVSS 9.8 — Critical): Improper certificate validation during session establishment may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway.[emaillocker id="1283"]

CVE-2026-85103 (CVSS 9.8 — Critical): A heap overflow in the VPN certificate ASN.1 decoding flow may allow a remote attacker to remotely execute arbitrary code on the management and Security Gateway.

These vulnerabilities collectively present severe risks to enterprise operations, particularly for organizations relying heavily on network security appliances.

RECOMMENDATION:

We recommend you to refer below link: https://support.checkpoint.com/results/sk/sk1000117/ https://support.checkpoint.com/results/sk/sk1000118/

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu