What happened
On 9 September 2026, Check Point released emergency updates for CVE-2026-85102 and CVE-2026-85103 and began rolling out Check Point Live Patch protection. The vendor describes both issues as internally discovered and recommends the latest release-specific Jumbo Hotfix where automatic protection is not being used.
CVE-2026-85102 is an improper certificate-validation flaw in VPN negotiation that can allow an unauthenticated remote attacker to execute arbitrary code on a Check Point Security Gateway. CVE-2026-85103 is a heap-based overflow in VPN certificate ASN.1 decoding that can allow remote code execution on Check Point Security Gateway and Security Management Server systems. CERT-EU assigns both a CVSS score of 9.8.
CERT-EU lists Security Gateway, Security Management Server and Spark Firewall deployments across R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10, R81.10.X, R81.20, R82, R82.00.X and R82.10 as affected. Several listed branches are end of support, creating a migration or exception decision in addition to the immediate hotfix requirement.
On 10 September 2026, CERT-EU directed organisations to prioritise internet-facing and perimeter appliances for immediate hotfixing. Attribution posture: Check Point reports no indication of active exploitation and names no actor. The cited Check Point and CERT-EU sources did not publish exploit hashes, filenames, IP addresses, domains or other attacker infrastructure.
Why this matters now
CERT-EU’s publication moves the issue from a vendor-only disclosure into authoritative perimeter guidance. Both vulnerabilities can permit unauthenticated remote code execution, and one reaches Security Management Server systems as well as gateways, increasing the consequence of missed or incomplete deployment.
The affected range includes supported and end-of-support releases. Enterprises cannot treat this as a routine maintenance push when branch upgrades, Spark firmware availability, cluster sequencing or change freezes may complicate deployment. Exceptions need named owners, isolation measures and deadlines.
Check Point reports no indication of active exploitation, but that statement does not lower the placement risk. VPN negotiation and certificate-processing surfaces are reachable before ordinary user authentication, while successful code execution on a security gateway can undermine the control intended to protect other assets.
Live Patch can reduce exposure, but assumed rollout is not evidence. Security teams need appliance-level proof that the relevant processes are covered, together with a compromise review proportionate to external exposure and management-plane privilege.
The decision for security leaders
Set remediation priority by placement, not CVSS alone. Internet-facing VPN gateways, Security Management Servers and appliances bridging sensitive network zones should precede internally isolated devices, while end-of-support exceptions require explicit executive acceptance.
Require appliance-level verification rather than accepting a central deployment status. The official CheckMates thread shows cplp list as the command used to inspect live-patch state for CVE-2026-85102 and CVE-2026-85103.
Separate remediation from compromise assessment. Where a vulnerable certificate-processing surface was externally reachable, retain relevant logs and configuration evidence before declaring closure, even though the vendor has not reported active exploitation.
Evidence of closure
- Asset register accounts for every affected appliance and release.
- Saved cplp list output proves relevant live-patch coverage.
- Change records confirm hotfix installation on non-Live-Patch systems.
- Forensic review documents no evidence of unauthorised gateway activity.
The Security.io assessment
The absence of known exploitation is meaningful but temporary evidence. The combination of pre-authentication reachability, arbitrary code execution and security-control placement supports emergency treatment without representing exploitation as confirmed.
Legacy branches are the most significant governance problem. A technically available hotfix does not resolve unsupported-platform risk, delayed firmware pipelines or the possibility that future issues receive weaker remediation support. Those systems need a dated migration decision.
Centralised management exposure increases blast radius because a compromised management system can influence policy and trust across multiple gateways. Remediation assurance should therefore include administrative integrity and configuration review, not merely service availability after reboot.
Questions for the morning meeting
- Which internet-facing gateways process Remote Access or Site-to-Site VPN certificates?
- Are any affected appliances running end-of-support branches?
- Does live-patch output prove protection on every relevant process?
- What telemetry would distinguish patching from prior compromise?