2026-012: Critical Vulnerabilities in Check Point Products

Imported from official source

Advisory

Cybersecurity Classified by Officially

Critical Vulnerabilities in Check Point Products

  • 10/09/2026 --- v1.0 -- Initial publication
  • On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-Site VPN [1,2]. Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances [1,2].

    CERT-EU strongly recommends applying the available hotfixes as soon as possible, prioritising internet-facing and perimeter appliances.

    The vulnerability CVE-2026-85102, with a CVSS score of 9.8, is an improper certificate-data validation vulnerability in the VPN negotiation flow of Check Point Security Gateway that allows an unauthenticated, remote attacker to execute arbitrary code on the affected appliance [1]. The issue affects deployments using either Site-to-Site VPN or Remote Access VPN [1].

    The vulnerability CVE-2026-85103, with a CVSS score of 9.8, is a heap overflow vulnerability in the VPN certificate ASN.1 decoding flow of Check Point Security Gateway and Security Management Server that allows a remote attacker to execute arbitrary code on the affected appliance [2]. Unlike CVE-2026-85102, this vulnerability affects both the Security Gateway and the Security Management Server [2].

    The following Check Point products and versions are affected [1,2]:

  • Check Point Security Gateway — R80, R80.10, R80.20, R80.30, R80.40 (End of Support)
  • Check Point Security Gateway — R81, R81.10 (End of Support)
  • Check Point Security Management Server — all versions listed above
  • Check Point Spark Firewall (Centrally Managed and Locally Managed) — all versions listed above
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://cert.europa.eu/publications/security-advisories/2026-012/

    Officially imported this from CERT-EU’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    CERT-EU — imported from official source
    Official source
    https://www.cert.europa.eu/publications/security-advisories-rss RSS
    Imported
    September 15, 2026 20:57
    Versions
    1 recorded
    Identity
    security-advisories-10949

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.