Executive Summary

    On September 9th, 2026, Check Point released emergency security updates for two critical vulnerabilities in the VPN certificate handling of its Quantum product line. The vulnerabilities could allow an unauthenticated, remote attacker to compromise and execute code on affected Check Point systems. Check Point has released emergency patches to fix these flaws.

    CVE-2026-85103 impacts both Security Gateways and Security Management systems, while CVE-2026-85102 specifically impacts Security Gateways during VPN connections. Both vulnerabilities affect how these systems process certificates used during VPN communication. Because these systems provide firewall and VPN access and manage security policies across enterprise environments, successful exploitation could provide attackers with a foothold at the network perimeter and a potential path into sensitive internal networks.

    Vulnerabilities enabling unauthenticated code execution on internet-facing VPN infrastructure have historically been weaponized by threat actors shortly after their disclosure. Beazley Security recommends affected organizations apply available fixes as soon as possible.

    Affected Systems or Products

    Product

    Affected Versions

    Fixed Versions

    Security Gateway, Security Management, and Spark Firewall

    R81 (EOS), R81 (EOS), R81.10 (EOS), R81.10 (EOS), R81.10.X, R81.10.X, R81.20, R81.20, R82, R82, R82.00.X, R82.00.X, R82.10, R82.10

    R82.20

    This table has been condensed to include products affected by both CVEs. According to Check Point’s advisory, customers that have enabled automatic installation through Check Point LivePatch have already been protected.

    Mitigations / Workarounds

    Check Point has released fixes, and it is recommended that affected customers apply the available patches. Organizations that cannot patch immediately can temporarily reduce risk of exposure by:

    • Disabling implied VPN rules for Site-to-Site VPN connections.

    • Restrict UDP ports 500 and 4500 to the expected peer IP addresses your tunnels require.

    Both steps narrow which hosts can begin a VPN negotiation with the appliance to reduce exposure but will break tunnels from peers that are not explicitly permit.

    Patches

    Check Point resolved both vulnerabilities through its LivePatch service, and customers that have enabled LivePatch will receive the fixes automatically. Administrators managing devices without LivePatch must install the Jumbo Hotfix Accumulator package for their release branch. Full details are in Check Point's advisories, sk1000117 and sk1000118.

    According to Check Point’s advisories, the following steps can be taken in Expert mode to validate that LivePatch is installed and active:

    [Expert@Host:0]# cpinfo -y CPupdates
    [CPUpdates]
    BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE Take: 24

    For specific LivePatch validation, run in Expert mode:

    • On a Security Gateway / ClusterXL member: cplp list

    • On a Scalable Platform Security Group: g_all cplp list

    Technical Details

    Both vulnerabilities affect how certificates are processed during VPN connections. Because this certificate data is processed before a user’s identity is verified within the authentication flow, an unauthenticated remote attacker can supply a malformed certificate during the VPN handshake phase, causing the gateway to process untrusted input, ultimately enabling arbitrary code execution.

    CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoding process that can allow a remote attacker to execute arbitrary code on affected Security Gateways and Security Management systems. ASN.1 is used to encode certificate data, and a specially crafted certificate can corrupt heap memory as the appliance attempts to parse attacker-controlled fields. An attacker could exploit this memory corruption to achieve arbitrary code execution.

    CVE-2026-85102 involves improper certificate validation during session establishment. According to the sk1000117 security advisory, "Improper validation of certificate data during VPN negotiation may allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway. The flaw fails to properly validate the trust of a presented certificate, allowing an unauthenticated attacker to progress VPN negotiation far enough to execute code on an affected gateway.

    Check Point has not published additional technical detail regarding these flaws, and no public proof-of-concept exploits have been reported at the time of disclosure. Due to the critical nature of these vulnerabilities and potential exposure of VPN services to internet facing traffic, Beazley Security recommends affected organizations apply available security updates immediately.

    How Beazley Security is responding

    Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.

    We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.

    If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team.