Critical RCE Vulnerabilities Found in Check Point VPN Gateways
In short: On 9 September 2026, Check Point released emergency hotfixes for two critical vulnerabilities (CVE-2026-85102 and CVE-2026-85103), both with CVSS 9.8, affecting Security Gateway, Security Management Server, and Spark Firewall deployments using Remote Access VPN or Site-to-Site VPN. Both flaws allow unauthenticated remote attackers to execute arbitrary code on affected appliances. CERT-EU urges immediate patching, prioritising internet-facing and perimeter devices.
This summary was generated automatically by AI from CERT-EU's publication. It is our own text, not a copy of the original — facts, figures and quotes belong to the source, linked above and below.
What changed?
- 1CVE-2026-85102: improper certificate-data validation in VPN negotiation flow, CVSS 9.8, affects Security Gateway with Site-to-Site or Remote Access VPN
- 2CVE-2026-85103: heap overflow in VPN certificate ASN.1 decoding, CVSS 9.8, affects both Security Gateway and Security Management Server
- 3Affected: Security Gateway R80–R82.10, Security Management Server (all listed versions), Spark Firewall (centrally and locally managed)
- 4Hotfixes released 9 September 2026; CERT-EU recommends immediate application
Why it matters
Unauthenticated RCE on widely used enterprise VPN/firewall appliances is critical infrastructure risk — attackers can compromise perimeter defenses without credentials, potentially exposing internal networks including VoIP/SIP infrastructure behind these gateways.
What it means for AI agents and contact centers
If your company uses Check Point Security Gateway/Spark Firewall for VPN or perimeter protection around SIP/Asterisk/VoIP servers or cloud infrastructure, these appliances must be patched immediately as they could be a direct entry point for attackers into the network hosting voice AI systems.
Sources
- CERT-EUOfficialPrimary sourceOriginal article →„2026-012: Critical Vulnerabilities in Check Point Products“Licence: CC BY 4.0 (CERT-EU legal notice; Commission Decision 2011/833/EU) · our summary (content changed)
- Published by source
- —
- Found by our system
- 2 Oct 2026, 22:23
- Summary generated
- 2 Oct 2026, 22:25
This article was written by AI from the original source. Facts, numbers and prices come from the source; missing values are marked “Not specified”. Legal notice, copyright and privacy