CTIPilot
← Back to the live brief
HIGHCVE-2026-85103 +1NATOA2vulnerability

Check Point Quantum Security Gateway / Management Server / Spark Firewall: two unauthenticated CVSS 9.8 pre-auth RCE flaws in VPN certificate processing (CVE-2026-85103 heap overflow, CVE-2026-85102 improper cert validation)

Two pre-auth code-execution flaws sit in the certificate-processing step every VPN negotiation runs before a user ever authenticates

Defender actions

  • Apply LivePatch Take 24 or the appropriate Jumbo Hotfix Accumulator to every Check Point Security Gateway, Management Server and Spark Firewall now; no workaround exists for Remote Access VPN or the locally-managed Spark Firewall short of patching.

Analysis

Check Point published two Critical-severity advisories (last modified 2026-09-09) for its VPN certificate-handling code, both triggered during certificate processing before authentication completes and both discovered internally with no external researcher credited (Check Point, advisory sk1000118, 2026-09-07; sk1000117, 2026-09-07). CVE-2026-85103 (CVSS 9.8) is "a heap overflow in the VPN certificate ASN.1 decoding flow" that "may allow a remote attacker to remotely execute arbitrary code on the management and Security Gateway" (Check Point, sk1000118). CVE-2026-85102 (CVSS 9.8, CWE-295 improper certificate validation) is an authentication-bypass-to-RCE in Remote Access and Site-to-Site VPN negotiation: "improper validation of certificate data during VPN negotiation may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway" (Check Point, sk1000117), reachable against the Security Gateway and Spark Firewall. Affected: R81.20, R82, R82.10, and the end-of-support R80/R80.10/R80.20/R80.30/R80.40/R81/R81.10 lines and their .x builds; R82.20 is confirmed not affected. "Both vulnerabilities were discovered internally by Check Point, and there are no reports of active exploitation as of September 9, 2026" (Forkast News, 2026-09-09); this is a distinct certificate-processing defect from the June 2026 IKEv1 key-exchange flaw (CVE-2026-50751) already on CISA KEV. Fix is delivered via Check Point LivePatch Take 24 (automatic if enabled) or Jumbo Hotfix Accumulator (R82.10 Take 44+, R82 Take 126+, R81.20 Take 166+), plus dedicated Spark Firewall builds (R82.00.10 Build 2325+, R81.10.17 Build 4968+). No workaround exists for the locally-managed Spark Firewall; for Site-to-Site VPN the only interim mitigation is disabling implied VPN rules and manually restricting UDP/500 and UDP/4500 to specific peer IPs, which does not apply to Remote Access VPN.

Cited evidence

A heap overflow in the VPN certificate ASN.1 decoding flow may allow a remote attacker to remotely execute arbitrary code on the management and Security Gateway.

Check Point (vendor advisory sk1000118) 2026-09-07

Improper validation of certificate data during VPN negotiation may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway.

Check Point (vendor advisory sk1000117) 2026-09-07

Both vulnerabilities were discovered internally by Check Point, and there are no reports of active exploitation as of September 9, 2026.

Forkast News 2026-09-09

Sources3

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.