Full Report
Check Point security advisory (AV26-902)
Analysis Summary
# Vulnerability: Multiple Critical Flaws in Check Point VPN and Management Systems
## CVE Details
- **CVE ID:** CVE-2026-85102
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-287 (Improper Authentication) / CWE-94 (Code Injection)
- **CVE ID:** CVE-2026-85103
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-122 (Heap-based Buffer Overflow)
## Affected Systems
- **Products:**
- Security Gateway
- Check Point Spark Firewall
- Security Management Server
- **Versions:** Multiple versions (Specific version mapping is provided in the individual vendor SK articles).
- **Configurations:**
- Systems utilizing Site-to-Site VPN.
- Systems utilizing Remote Access VPN.
- Systems performing ASN.1 decoding (standard for certificate handling/handshakes).
## Vulnerability Description
- **CVE-2026-85102:** An authentication bypass vulnerability exists within the Remote Access and Site-to-Site VPN components. An unauthenticated attacker can bypass security controls to achieve Remote Code Execution (RCE) on the gateway, potentially gaining full control over the network traffic and the device itself.
- **CVE-2026-85103:** A heap-based buffer overflow vulnerability exists in the ASN.1 decoding engine. By sending a specially crafted packet, an attacker can trigger memory corruption, leading to Remote Code Execution (RCE) with elevated privileges.
## Exploitation
- **Status:** Under Investigation / PoC potential (Per initial advisory release).
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High
- **Integrity:** High
- **Availability:** High
## Remediation
### Patches
- Check Point has released hotfixes and Jumbo Hotfix Accumulators for affected versions. Users should refer to the following specific Support Knowledge (SK) articles for version-specific downloads:
- Refer to SK1000117 for CVE-2026-85102.
- Refer to SK1000118 for CVE-2026-85103.
### Workarounds
- If patching is not immediately possible, restrict access to VPN services to known/trusted IP ranges.
- Disable unused VPN communities and Remote Access features where not strictly required.
- Ensure "Internal" management interfaces are not exposed to the public internet.
## Detection
- **Indicators of Compromise:** Monitor for unusual crash logs in VPN processes (e.g., `vpnd`). Look for unauthorized administrative users created or modified in the Management Server logs.
- **Detection Methods:** Deploy updated IPS signatures provided by Check Point. Audit logs for failed or unusual IKE/VPN negotiations from unknown external sources.
## References
- Check Point Advisory CVE-2026-85102: hxxps[://]support[.]checkpoint[.]com/results/sk/sk1000117/
- Check Point Advisory CVE-2026-85103: hxxps[://]support[.]checkpoint[.]com/results/sk/sk1000118/
- Check Point Security Blog: hxxps[://]blog[.]checkpoint[.]com/security/
- Canadian Centre for Cyber Security Advisory: hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/check-point-security-advisory-av26-902