Network security vendor Check Point has released patches for two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, affecting its widely used VPN gateways and security management products. Both vulnerabilities have been assigned a CVSS score of 9.8, indicating a severe risk. If exploited, they could allow a remote, unauthenticated attacker to execute arbitrary code on affected devices. The flaws reside in the processing of VPN certificates and impact internet-facing security gateways, making them high-value targets. Although Check Point discovered the flaws internally and has found no evidence of in-the-wild exploitation, security bodies like CERT-EU are strongly recommending that organizations apply the available hotfixes as a matter of urgency to prevent potential compromise.
The two vulnerabilities affect how Check Point products handle VPN certificates during connection setup.
CVE-2026-85102: This is an improper certificate trust validation vulnerability that occurs during VPN negotiation. An attacker could potentially leverage this flaw to bypass authentication mechanisms. It affects Security Gateways and Spark Firewalls when configured with Site-to-Site or Remote Access VPN.
CVE-2026-85103: This is a heap-based buffer overflow vulnerability in the code that decodes the ASN.1 structure of a VPN certificate. By sending a specially crafted certificate, an attacker could cause a buffer overflow, leading to a crash or, potentially, arbitrary code execution. This flaw affects not only the gateways but also the Security Management Server.
For both vulnerabilities:
The vulnerabilities impact a range of Check Point's core security products, including:
Affected versions include, but may not be limited to, R82.10, R82, and R81.20. Customers should consult Check Point's security advisories for a complete list of affected versions and products.
As of the disclosure on September 9, 2026, Check Point stated there was no evidence of active exploitation. The vulnerabilities were discovered by Check Point's internal research team. However, vulnerabilities in perimeter security appliances like VPN gateways are highly prized by threat actors. Once technical details become public, it is common for attackers to reverse-engineer the patch and develop exploits rapidly. Therefore, organizations should operate under the assumption that exploitation is likely to occur soon.
Successful exploitation of these vulnerabilities would be catastrophic for an organization. An attacker gaining remote code execution on a perimeter security gateway could:
Compromise of the Security Management Server could allow an attacker to push malicious policies to all managed firewalls, effectively taking over the entire network security infrastructure.
The following patterns may help identify vulnerable or compromised systems:
log_sourceCheck Point VPN Logs (vpnd.log)vpnd).network_traffic_patternprocess_namevpndvpnd process on the gateway for unexpected high CPU usage, memory consumption, or crashes.top, dmesg).vpnd process crashes or a high volume of failed VPN authentications from a single source IP.Applying the hotfixes or upgrading to a patched version is the most effective way to remediate these vulnerabilities.
Mapped D3FEND Techniques:
Using an IPS with signatures for these vulnerabilities can help detect and block exploit attempts.
Mapped D3FEND Techniques:
Restricting which IP addresses can initiate VPN connections can reduce the attack surface.
Mapped D3FEND Techniques:
The immediate and highest priority action is to apply the hotfixes provided by Check Point to all affected Security Gateways, Security Management Servers, and Spark Firewalls. Given the 9.8 CVSS score and the internet-facing nature of these devices, the risk of weaponization is extremely high. Organizations should use Check Point's management server to deploy the Jumbo Hotfix Accumulator or apply the patches manually. For customers with the LivePatch service, verify that the fix has been successfully applied. Do not delay patching these perimeter devices; they are the first line of defense and a prime target for attackers seeking entry into a network.
While patching is in progress, security teams should enhance monitoring of their Check Point infrastructure. Ingest logs from the vpnd process into a SIEM and create alerts for frequent or unexpected process crashes, which could indicate failed exploit attempts against the heap overflow vulnerability (CVE-2026-85103). Additionally, monitor network traffic for a high volume of failed IKE negotiations from a single source IP, as this could represent scanning or brute-force attempts against the certificate validation flaw (CVE-2026-85102). This proactive monitoring can help detect targeting activity and provide an early warning of an impending attack.
Check Point discloses and releases patches for CVE-2026-85102 and CVE-2026-85103.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.