Check Point Patches Critical VPN Vulnerabilities in Security Gateway and Spark Firewall

Connected campus representing cyber-physical security convergence

Check Point has patched two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a CVSS score of 9.8, in the VPN functionality of its Security Gateway and Spark Firewall products, SecurityWeek reported. The flaws stem from a certificate-validation issue and an ASN.1 heap overflow bug that together could allow unauthenticated remote code execution.

Check Point said its own researchers discovered both vulnerabilities internally, and the company has not confirmed any in-the-wild exploitation to date. Fixes are available in versions R82.10, R82, and R81.20.

Why it matters: VPN gateways sit at the network perimeter for a large share of enterprise and critical-infrastructure networks, making unauthenticated RCE flaws in this class of product a high-priority patch item regardless of whether active exploitation has been observed yet — the same category of flaw was exploited in the wild within days at other vendors this quarter.

Source: SecurityWeek, September 11, 2026.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *