Check Point's Patch Gap Leaves VPN Flaws Exposed
Two 9.8-rated certificate flaws in Check Point gateways carry fixes that some customers say they cannot access.
Check Point says it has patched two critical certificate-handling flaws in its firewall and management products, but the customer thread that followed its September 9 notice describes something messier: branches with no fix, automatic updates that never arrived, and mitigation guidance too vague to act on. Both flaws carry a CVSS score of 9.8 and could let an unauthenticated remote attacker execute code, according to Check Point's own records.
What the two flaws actually do
The first, CVE-2026-85102, is a failure to properly validate certificate trust during VPN negotiation. Its CVE record states that an unauthenticated remote attacker may be able to run code on the Security Gateway, Check Point's firewall appliance line.
The second, CVE-2026-85103, is a heap-based buffer overflow that occurs while the product decodes the ASN.1 structure of a VPN certificate. That one reaches further: its record says an unauthenticated remote attacker may be able to run code on Quantum Security Management and Quantum Security Gateway systems. That includes the Security Management Server, the console administrators use to configure the gateways themselves.
Check Point assigned both identifiers and both scores itself. The company said it found the flaws internally and has no indication that either has been used in an attack. Neither flaw has published indicators of compromise.
Who is listed as affected
Both CVE records give the same affected list — three Quantum branches, each keyed to a Jumbo Hotfix take level:
- R82.10 with Jumbo Hotfix Take 43 or below
- R82 with Jumbo Hotfix Take 125 or below
- R81.20 with Jumbo Hotfix Take 165 or below
Those are the versions the records mark as affected, not the versions that contain the fix. The list covers three Quantum branches and gives no version information for anything else.
An advisory from the Canadian Center for Cyber Security, published the same evening, lists a broader set of products but no versions at all. It names Security Gateway, Security Management Server, and Spark Firewall, Check Point's small-business line. Spark appears twice — once for deployments using Site-to-Site or Remote Access VPN, and once without that condition.
Neither Check Point's notice nor any public record reviewed for the article states which Spark or Security Management versions are affected, which builds contain the fix, or what specific conditions the company says the flaws require.
A question about VPN blade configuration
In the same community thread, a Check Point staff member was asked whether gateways with the VPN software blade turned off are affected by CVE-2026-85103. The staff member replied that the issue concerns certificate processing, so it could, in theory, be triggered in an environment without a VPN but with VPN certificates present.
That answer matters because it widens the population of systems administrators may need to think about. A gateway that never terminates a VPN tunnel is not automatically outside the blast radius if certificates are still sitting on it.
Two routes to a fix — and a branch left out
Check Point gave customers two paths. The first is Check Point Live Patch. The company says customers using it are protected automatically as the rollout begins, which started on September 9. A Check Point employee said in the thread that Live Patch can be installed on top of any Jumbo Hotfix level in R81.20, R82.00 and R82.10, and named only those three versions.
The second is the Jumbo Hotfix. Check Point told customers to install the latest one for their deployed version once it became available.
That leaves R81.10 in an awkward spot. Two customers said in the thread that they are running R81.10 and will not be moving off it for weeks. One of them said no Jumbo Hotfix and no Live Patch was available for that branch, leaving mitigation as the only option.
The same customer described the advisory's mitigation as turning off implied rules for VPN, called it too vague to act on, and asked which configuration lines to comment out. The other asked how to apply the mitigation without affecting remote users. Neither question had an answer in the thread.
Updates that had not landed
Several customers said the automatic rollout had not reached them. Five separate accounts reported gateways were still on Take 18 or Take 17 of the urgent security update package on the day of the announcement. One of them posted an update log showing Take 18 installed on September 1 and nothing since.
That gap between a vendor's rollout schedule and what is actually sitting on customer hardware is the kind of thing that turns a patch release into a spreadsheet exercise. It also means the phrase "protected automatically" can be true in aggregate and false for any given appliance.
Several customers also reported that download links in the two advisories did not work for them. A Check Point staff member replied that the links had been checked and were working. One customer said afterward that the advisory links still failed in two browsers, while the link in the Live Patch article worked.
What the notice does not say
Check Point has not published indicators of compromise for either of the new flaws. Asked in the thread whether logs would show attempts to exploit them, a staff member said the company had seen no evidence of external exploitation, and that indicators of compromise only apply to exploits that already exist.
Nothing in the material reviewed for the article addresses whether installing the fix removes access an attacker may already have obtained. Check Point's advisories sk1000117 and sk1000118 are the documents it points customers to for affected products, mitigation guidance, and remediation steps.
A June and July pattern
This is not the first time this year that Check Point has pushed urgent fixes for these same products. In June and July, it patched critical flaws that it said were already being exploited when it announced them.
June's was CVE-2026-50751, an authentication bypass in Remote Access VPN and Mobile Access certificate validation. The U.S. Cybersecurity and Infrastructure Security Agency added it to its Known Exploited Vulnerabilities catalog on June 8.
July's was CVE-2026-16232, a SmartConsole authentication bypass, which CISA added to the same catalog on the day it was disclosed. It was one of three flaws Check Point patched that month, two of which affected the Security Management Server — the same component CVE-2026-85103 reaches.
The difference this time is the exploitation status. Check Point says both new flaws were found internally and shows no evidence of use in the wild. The June and July entries, by contrast, arrived with exploitation already confirmed and CISA catalog listings attached.
Why this matters for defenders
The practical problem for anyone running the listed branches is not the CVSS score. It is the distance between what Check Point says is fixed and what an administrator can actually verify on their own hardware. Five separate accounts in the vendor's own thread reported update packages stuck at Take 18 or Take 17, and R81.10 users say they have neither a Jumbo Hotfix nor Live Patch to install. If the automatic rollout has not reached a given gateway, the only remaining lever described in the thread is a mitigation several customers called unactionable, with no answers posted to their follow-up questions about which configuration lines to change or how to avoid disrupting remote users.
That suggests a patch-management gap that could outlast the disclosure itself, at least for deployments in the uncovered branches. The absence of indicators of compromise compounds it: without a published way to check retrospectively, a defender has little recourse beyond confirming their current take level and watching for the fix to appear. Given that two earlier flaws in these same products were already being exploited on disclosure day, confirming the exact build in place — and confirming the automatic update actually took effect rather than simply being scheduled — is the difference between a patched gateway and one that merely appears patched. Until Check Point publishes the conditions the flaws require and the builds that resolve them, treating the gap between advisory and appliance as the real exposure window is the safer assumption.
Sources
- The Hacker News Original source
- CVE-2026-85102 Also reporting
- CVE-2026-85103 Also reporting
- advisory from the Canadian Center for Cyber Security Also reporting
- Live Patch article Also reporting
- CVE-2026-50751 Also reporting
Continue Reading
Mandia's Amazon Board Seat and Its Logic
Cybersecurity veteran Kevin Mandia has joined Amazon's board, a move the company says reflects its commitment to security experience at all levels.
August M&A: Deals That Reshape Security
Thirty-three cybersecurity M&A deals were announced in August 2026, with AI, identity, and exposure management topping the shopping lists.
Police Spy Tech Use Hidden From Public
EFF says police evade scrutiny by hiding purchases of surveillance technology from the public.