Check Point has disclosed two critical vulnerabilities in its security products. The flaws, both carrying a near-maximum CVSS severity score of 9.8, allow unauthenticated attackers to execute remote code on affected systems.
While the vendor stated at the time of disclosure that it had seen no evidence of active exploitation, security researchers typically expect unauthenticated remote code execution (RCE) flaws to be targeted by threat actors within days of a public announcement.
Technical Impact: Gateways and Management Servers
The threat is comprised of two distinct vulnerabilities, CVE-2026-85102 and CVE-2026-85103. Both bypass the need for valid credentials, making them highly attractive to ransomware groups and state-sponsored actors.
CVE-2026-85102 stems from improper validation of certificate data during the VPN negotiation process. This flaw specifically targets Security Gateways, potentially allowing an attacker to gain a foothold on the network perimeter.
CVE-2026-85103 is a heap overflow vulnerability located in the VPN certificate ASN.1 decoder. Unlike the first flaw, this vulnerability affects both Security Gateways and Security Management Servers. The inclusion of the Management Server in the threat profile is particularly significant; a successful breach of the control console could grant an attacker lateral movement across the entire security architecture, enabling the modification of firewall rules or the deployment of malicious configurations to multiple gateways simultaneously.

Vulnerable Versions and Legacy Risks
According to security research reports, the vulnerabilities impact a wide range of Check Point’s portfolio, including Quantum gateways and Spark firewalls.
Organizations are urged to prioritize immediate upgrades to supported software versions or apply manual mitigations where possible. Entities running older versions are at heightened risk as they may not receive standard hotfixes.
Emergency Patching and Mitigations
For organizations that cannot apply mitigations immediately due to maintenance windows or legacy hardware constraints, security experts recommend the following temporary measures:
- Restricting Traffic: Limit access to UDP ports 500 and 4500 to known-good IP addresses or geofenced locations where possible.
- Certificate Monitoring: Closely audit VPN negotiation logs for unusual certificate exchange patterns or ASN.1 decoding errors.
- Management Isolation: Ensure that Security Management Servers are not exposed to the public internet and are only accessible via trusted administrative segments.
Given the unauthenticated nature of these new vulnerabilities, global security partners are treating the window for patching as extremely narrow.
