Check Point VPN: two CVSS 9.8 flaws, patch before the PoC
Dutch NCSC warns exploitation of Check Point VPN CVE-2026-85102 and CVE-2026-85103 is imminent. Pre-auth RCE on Security Gateway and Spark. Patch now.
If your office firewall says Check Point on the front, go check its version before you read the rest of this. CVE-2026-85102 and CVE-2026-85103 are both CVSS 9.8, both unauthenticated remote code execution, and both live in the VPN certificate path — the code that runs before anyone logs in. Check Point shipped fixes on September 9. On September 12 the Dutch national cyber agency told everyone to stop waiting.
What actually happened
Check Point found both bugs internally and patched them on September 9 under advisories sk1000117 and sk1000118, per SecurityWeek.
CVE-2026-85102 is improper validation of certificate data during VPN negotiation. It hits Security Gateway and Check Point Spark Firewall running Site-to-Site VPN or Remote Access VPN. CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoding flow, and its blast radius is wider — Security Management Server, Security Gateway and Spark Firewall. Fixes landed in the R82.10, R82 and R81.20 trains.
Then the escalation. The Nationaal Cyber Security Centrum published an advisory rating both the likelihood of exploitation and the impact as high, and said it expects exploitation attempts soon. No public proof-of-concept has surfaced yet and Check Point reports no evidence of in-the-wild abuse. That is the window, not the all-clear — patched edge appliances get diffed, and a pre-auth RCE in certificate parsing is exactly the class of bug that gets reverse-engineered into a working exploit within days.
Check Point's interim mitigation for Site-to-Site VPN: disable implied rules for VPN and manually define access on UDP/500 and UDP/4500 to the specific peer IPs. LivePatch customers get the fix automatically. Locally managed Spark boxes need the latest Jumbo hotfixes applied by hand.
Why this matters for your business
Note which product is on both lists. Spark is Check Point's small-business firewall line — the appliance in the closet at a 15-person shop, bought once, mounted, and never thought about again. This is not an enterprise-only patch cycle. It is aimed directly at the boxes nobody owns.
An edge VPN appliance is the worst possible place for a pre-auth bug. It is internet-facing by definition, it sits inside your perimeter by design, and the vulnerable code path runs before any credential check — so MFA, strong passwords and a tight user list buy you exactly nothing here. Compromise the gateway and the attacker is on your LAN with the device's own trust.
Three moves, in order. Patch or hotfix this week, not at the next maintenance window; if LivePatch is available to you, confirm it actually applied rather than assuming. If you cannot patch immediately, apply the UDP/500 and UDP/4500 peer restriction — it narrows who can even reach the vulnerable negotiation. Then find out who owns the box. Most small companies discover during an incident that the answer was a contractor who stopped invoicing in 2023.
Key takeaways
- CVE-2026-85102 and CVE-2026-85103 are both CVSS 9.8 pre-authentication RCE bugs in Check Point's VPN certificate handling
- 85102 affects Security Gateway and Spark Firewall on Site-to-Site or Remote Access VPN; 85103 also affects Security Management Server
- Check Point found both internally and patched September 9 in R82.10, R82 and R81.20 (advisories sk1000117, sk1000118)
- The Dutch NCSC rated likelihood and impact high on September 12 and expects exploitation attempts soon
- No public PoC yet and no confirmed in-the-wild exploitation — that is a patch window, not an all-clear
- Spark is the small-business line: this patch is aimed at the firewall in the closet nobody owns
Nobody at your company can name who patches the firewall? That is the finding, not the firewall. We map the systems a small team actually depends on and put an owner and an update path on each one. Send us your setup or see what we cover.
Sources: SecurityWeek, BleepingComputer.
- #check-point
- #cve-2026-85102
- #vpn-security
- #patch-management
- #small-business-it
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Apache OpenNLP CVE-2026-82617: a CVSS 10 that hangs
A crafted string can stall or crash any thread running OpenNLP's built-in email and URL name finders. Affected: 2.0.0-2.5.11. Fixed in 2.5.12. Why the score misleads.
Read itMistral Vibe: six CVEs say allowlists aren't sandboxes
HiddenLayer disclosed six command-allowlist bypasses in Mistral Vibe on September 11, four at CVSS 10.0. What an AI coding agent's approval prompt actually protects.
Read it