Full Report
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security
Analysis Summary
# Vulnerability: Check Point VPN Certificate RCE Flaws
## CVE Details
- **CVE ID:** CVE-2026-85102, CVE-2026-85103
- **CVSS Score:** 9.8 (Critical)
- **CWE:**
- CVE-2026-85102: Improper Certificate Validation
- CVE-2026-85103: CWE-122 (Heap-based Buffer Overflow)
## Affected Systems
- **Products:**
- Quantum Security Gateways (Firewall appliances)
- Quantum Security Management Servers
- Spark Firewalls (Small business line)
- **Versions:**
- R82.10: Jumbo Hotfix Take 43 or below
- R82: Jumbo Hotfix Take 125 or below
- R81.20: Jumbo Hotfix Take 165 or below
- **Configurations:**
- Primarily affects systems with Site-to-Site or Remote Access VPN enabled.
- **Note:** CVE-2026-85103 may affect systems even if the VPN software blade is disabled, provided VPN certificates are present on the environment.
## Vulnerability Description
Check Point disclosed two critical flaws related to certificate processing:
1. **CVE-2026-85102:** A failure to properly validate certificate trust during the VPN negotiation phase. This allows an unauthenticated remote attacker to potentially execute arbitrary code.
2. **CVE-2026-85103:** A heap-based buffer overflow occurring during the decoding of the ASN.1 structure of a VPN certificate. This vulnerability can lead to remote code execution (RCE) on both gateways and management servers.
## Exploitation
- **Status:** Not exploited (No known evidence of exploitation in the wild at the time of disclosure).
- **Complexity:** High (Vendor states exploitation is possible only "under specific conditions").
- **Attack Vector:** Network (Remote, unauthenticated).
## Impact
- **Confidentiality:** Critical (Full system compromise possible).
- **Integrity:** Critical (Full system compromise possible).
- **Availability:** Critical (System takeover or denial of service).
## Remediation
### Patches
Check Point has released fixes via two primary delivery methods:
- **Check Point Live Patch:** Automatic protection rolling out to customers on R81.20, R82.00, and R82.10.
- **Jumbo Hotfix:** Customers should install the latest Jumbo Hotfix Take for their respective versions (R81.20, R82, R82.10).
### Workarounds
- **Configuration Change:** Turning off "implied rules" for VPN (Note: Community feedback suggests this mitigation is vague and may impact remote user connectivity).
- **Legacy Systems:** No specific Jumbo Hotfix or Live Patch was initially mentioned for R81.10 and older; upgrading to a supported version is recommended.
## Detection
- **Indicators of Compromise:** No specific IOCs (file hashes or IPs) have been released yet.
- **Detection Methods:**
- Check the current "Take" version of your Jumbo Hotfix.
- Review Check Point `CPUSE` logs to confirm if the Live Patch (Take 18 or higher) has been successfully applied.
- Monitor for unusual ASN.1 decoding errors in system logs.
## References
- **Vendor Advisories:**
- CVE-2026-85102: hxxps[://]support[.]checkpoint[.]com/results/sk/sk1000117
- CVE-2026-85103: hxxps[://]support[.]checkpoint[.]com/results/sk/sk1000118
- Live Patch Info: hxxps[://]support[.]checkpoint[.]com/results/sk/sk185114
- **Government Advisory:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/check-point-security-advisory-av26-902