Check Point patches two CVSS 9.8 flaws in VPN certificate handling

Check Point has patched two certificate-handling bugs that score 9.8 and could let an unauthenticated attacker run code.

CSBadmin
1 Min Read

Check Point has pushed fixes for two critical certificate-handling bugs in its firewall and management products, and defenders should treat them as urgent.

Both flaws carry a CVSS score of 9.8. Either could let an unauthenticated attacker run code, Check Point warns, though only “under specific conditions” it has not described.

What went wrong lives in the certificate path. One bug, CVE-2026-85102, mishandles trust checks during VPN negotiation. The second, CVE-2026-85103, overflows a heap while parsing certificate ASN.1 data.

Security Gateway appliances and Spark Firewall units running Site to Site VPN or Remote Access VPN are exposed to the first bug. The second also reaches the Security Management Server that admins use to configure those devices.

The vendor notified its customer community on September 9 and started shipping fixes the same day. Both were found in-house, and Check Point says it has no evidence of exploitation.

Placement is what makes the pair dangerous. Trust checks are the step meant to keep strangers off a gateway, so a working exploit would need no password. Verify the fixed build on every gateway and management node, then watch for unusual VPN negotiation traffic.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.