started · updated
Check Point patches two critical VPN certificate vulnerabilities
Check Point has disclosed two critical vulnerabilities in its Quantum VPN infrastructure, both assigned a CVSS score of 9.8. The flaws, identified as CVE-2026-85102 and CVE-2026-85103, could allow unauthenticated remote attackers to execute arbitrary code during the VPN negotiation phase before authentication is finalized.
CVE-2026-85102 involves a failure to properly validate certificate trust, specifically affecting Security Gateways. CVE-2026-85103 is a heap-based buffer overflow occurring during the decoding of ASN.1 structures within VPN certificates; this flaw impacts both Security Gateways and the Security Management Server.
Check Point discovered both vulnerabilities internally and stated there is no indication they have been exploited in the wild. The company began delivering patches on September 9. Affected versions include various Quantum branches, such as R82.10, R82, and R81.20, depending on specific Jumbo Hotfix levels.