Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-11 ยท updated: 2026-09-11 ยท tags: [incident, check-point, quantum, vpn, rce, edge-device, patching] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, financial-services] ยท au_impact: true

Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates, both rated CVSS 9.8 by the vendor and both allowing an unauthenticated remote attacker to execute code "under specific conditions" that Check Point has declined to describe.

Attribute Detail
CVEs CVE-2026-85102 (certificate trust validation), CVE-2026-85103 (ASN.1 heap overflow)
CVSS 9.8 each (vendor-assigned)
Products Security Gateway; Quantum Security Management Server; Spark Firewall (per CCCS advisory)
Affected builds R82.10 (Take โ‰ค43), R82 (Take โ‰ค125), R81.20 (Take โ‰ค165)
Remediation Check Point Live Patch and Jumbo Hotfix, both rolling from 2026-09-09
Exploited No indication of exploitation as at 2026-09-10

Check Point says it found both flaws itself and has published no indicators of compromise. The rollout has been uneven in practice: customers on the R81.10 branch reported in the vendor's own community thread that neither Live Patch nor a Jumbo Hotfix was available to them, leaving the advisory's vaguely worded VPN implied-rules mitigation as the only option, while several other customers reported the automatic rollout had not reached their gateways and others reported broken download links in the advisories. A vendor staff member noted that CVE-2026-85103 concerns certificate processing, so it could in principle be triggered without VPN enabled where VPN certificates are present. The vendor has not stated which Spark or Security Management versions are affected, which builds contain the fix, what the "specific conditions" are, or whether installing the fix removes access an attacker may already hold. See cve-2026-85102.md and cve-2026-85103.md.