Security.io Intelligence DeskFriday, 11 September 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Network Security · Executive briefing

Check Point VPN flaws expose gateways and management servers

Two unauthenticated code-execution paths affect Check Point gateway and management products, including end-of-support branches; CERT-EU’s new guidance prioritises perimeter remediation.

Network SecurityVulnerability ManagementIncident Response
Why it is in today’s brief

Check Point disclosed the flaws on 9 September, but CERT-EU’s 10 September advisory is the materially new authoritative guidance inside the edition window. The story warrants inclusion because unauthenticated code execution reaches perimeter gateways and management servers across supported and end-of-support branches. It creates a same-day exposure, remediation-evidence and legacy-exception decision without claiming exploitation has occurred.

Read first

Check Point disclosed CVE-2026-85102 and CVE-2026-85103, two critical VPN certificate-processing vulnerabilities capable of unauthenticated remote code execution. CERT-EU now urges immediate hotfixing of affected perimeter and management appliances.

Act now

Inventory every affected Check Point appliance and release branch.

Accountable owner

Network security director with the vulnerability-management and incident-response leads

Decision horizon

Immediate inventory and protection validation; same-day remediation for internet-facing and management-plane systems.

AssessmentHigh confidence
Emerging riskActive-exploitation confirmation, vendor indicators, affected-version revisions, release-specific deployment problems and evidence that Live Patch coverage is incomplete.

What happened

On 9 September 2026, Check Point released emergency updates for CVE-2026-85102 and CVE-2026-85103 and began rolling out Check Point Live Patch protection. The vendor describes both issues as internally discovered and recommends the latest release-specific Jumbo Hotfix where automatic protection is not being used.

CVE-2026-85102 is an improper certificate-validation flaw in VPN negotiation that can allow an unauthenticated remote attacker to execute arbitrary code on a Check Point Security Gateway. CVE-2026-85103 is a heap-based overflow in VPN certificate ASN.1 decoding that can allow remote code execution on Check Point Security Gateway and Security Management Server systems. CERT-EU assigns both a CVSS score of 9.8.

CERT-EU lists Security Gateway, Security Management Server and Spark Firewall deployments across R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10, R81.10.X, R81.20, R82, R82.00.X and R82.10 as affected. Several listed branches are end of support, creating a migration or exception decision in addition to the immediate hotfix requirement.

On 10 September 2026, CERT-EU directed organisations to prioritise internet-facing and perimeter appliances for immediate hotfixing. Attribution posture: Check Point reports no indication of active exploitation and names no actor. The cited Check Point and CERT-EU sources did not publish exploit hashes, filenames, IP addresses, domains or other attacker infrastructure.

Why this matters now

CERT-EU’s publication moves the issue from a vendor-only disclosure into authoritative perimeter guidance. Both vulnerabilities can permit unauthenticated remote code execution, and one reaches Security Management Server systems as well as gateways, increasing the consequence of missed or incomplete deployment.

The affected range includes supported and end-of-support releases. Enterprises cannot treat this as a routine maintenance push when branch upgrades, Spark firmware availability, cluster sequencing or change freezes may complicate deployment. Exceptions need named owners, isolation measures and deadlines.

Check Point reports no indication of active exploitation, but that statement does not lower the placement risk. VPN negotiation and certificate-processing surfaces are reachable before ordinary user authentication, while successful code execution on a security gateway can undermine the control intended to protect other assets.

Live Patch can reduce exposure, but assumed rollout is not evidence. Security teams need appliance-level proof that the relevant processes are covered, together with a compromise review proportionate to external exposure and management-plane privilege.

The decision for security leaders

Set remediation priority by placement, not CVSS alone. Internet-facing VPN gateways, Security Management Servers and appliances bridging sensitive network zones should precede internally isolated devices, while end-of-support exceptions require explicit executive acceptance.

Require appliance-level verification rather than accepting a central deployment status. The official CheckMates thread shows cplp list as the command used to inspect live-patch state for CVE-2026-85102 and CVE-2026-85103.

Separate remediation from compromise assessment. Where a vulnerable certificate-processing surface was externally reachable, retain relevant logs and configuration evidence before declaring closure, even though the vendor has not reported active exploitation.

Evidence of closure

  • Asset register accounts for every affected appliance and release.
  • Saved cplp list output proves relevant live-patch coverage.
  • Change records confirm hotfix installation on non-Live-Patch systems.
  • Forensic review documents no evidence of unauthorised gateway activity.

The Security.io assessment

The absence of known exploitation is meaningful but temporary evidence. The combination of pre-authentication reachability, arbitrary code execution and security-control placement supports emergency treatment without representing exploitation as confirmed.

Legacy branches are the most significant governance problem. A technically available hotfix does not resolve unsupported-platform risk, delayed firmware pipelines or the possibility that future issues receive weaker remediation support. Those systems need a dated migration decision.

Centralised management exposure increases blast radius because a compromised management system can influence policy and trust across multiple gateways. Remediation assurance should therefore include administrative integrity and configuration review, not merely service availability after reboot.

Questions for the morning meeting

  • Which internet-facing gateways process Remote Access or Site-to-Site VPN certificates?
  • Are any affected appliances running end-of-support branches?
  • Does live-patch output prove protection on every relevant process?
  • What telemetry would distinguish patching from prior compromise?

Related intelligence

Shared decision context

Appointments, dinners & sponsored intelligence

Current paid placements · clearly separated
Open calendar
Sponsor's Notice · Security.io

Private CISO Roundtable: The 2027 Security Agenda

A closed-door, vendor-neutral discussion for senior security leaders hosted by Security.io.

Request details →
Invitation only
Sponsor's Notice · Security.io

Security.io CISO Dinner: Decisions That Cannot Wait

An invitation-only dinner for CISOs and deputies focused on consequential security decisions.

Request an invitation →
Black Hat week
Paid Placement · Security.io

Security.io at Black Hat: Executive Intelligence Dinner

A private dinner and briefing for security leaders during Black Hat week.

Join the interest list →