Security1 publisher3 min readPublished
Check Point patches two 9.8 VPN certificate flaws without naming what triggers them
Check Point assigned the CVE identifiers and the 9.8 scores itself and shipped fixes on September 9, so there is no outside read on how reachable the bugs are. Customers on R81.10 get neither a hotfix nor Live Patch.
The Watch · Security desk

What happened
- Check Point disclosed two certificate-handling flaws on September 9 in a notice to its customer community and began delivering fixes the same day.
- CVE-2026-85102 is a failure to properly validate certificate trust during VPN negotiation, and its record says an unauthenticated remote attacker may be able to run code on the Security Gateway.
- CVE-2026-85103 is a heap-based buffer overflow during decoding of a VPN certificate's ASN.1 structure, reaching both Quantum Security Gateway and Quantum Security Management.
- Both records carry a CVSS score of 9.8, and Check Point assigned the identifiers and the scores itself.
- Check Point says it found both flaws internally and has no indication that either has been used in an attack.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint With the triggering conditions withheld, no operator can rule a gateway out of scope on evidence; installing the fix is the only way to close the question.
- exposure Estates parked on R81.10 for the next several weeks hold the risk with nothing to install, and their fallback touches the same VPN configuration their remote users depend on.
- contradiction Check Point's own answer about certificate processing puts systems in scope that the Canadian advisory's VPN qualifier appears to exclude, so scoping from the advisory alone can miss gateways.
- precedent Given what happened to the June and July bugs in this line, the working assumption for a certificate path in these appliances is that it gets weaponised, which sets the patch window rather than today's clean telemetry.
The exposure question turns on one reply in the customer thread. Asked whether gateways with the VPN software blade switched off are affected by CVE-2026-85103, a Check Point staff member said the issue is certificate processing, so it could in theory be triggered in an environment with no VPN but with VPN certificates present [10]. Read that against the advisory from the Canadian Centre for Cyber Security, published the same evening, which names Security Gateway, Security Management Server and the Spark small-business line with no version data at all, and which names Spark twice, once for deployments using Site-to-Site or Remote Access VPN and once with no such condition [9].
Check Point has not said what the specific conditions are [2]. The reachable set is therefore unknown to the customer, and the score does not narrow it. What is on offer instead is a version list: R82.10 at Jumbo Hotfix Take 43 or below, R82 at Take 125 or below, R81.20 at Take 165 or below, marked as affected rather than fixed, covering three Quantum branches with no version information for anything else [8].
Check Point says Live Patch users are protected automatically as the rollout begins, and an employee said it installs on top of any Jumbo Hotfix level in R81.20, R82.00 and R82.10 [11]. Five accounts said it had not reached them, reporting gateways still on Take 18 or Take 17 of the urgent security update package on the day of the announcement, one with an update log showing Take 18 installed on September 1 and nothing since [15]. Several customers also said the advisory download links failed for them; a staff member replied that the links had been checked and were working; one customer then reported the advisory links still failing in two browsers while the link in the Live Patch article worked [16]. Automatic protection is verifiable only at the take level on the gateway.
R81.10 has no route. Two customers said they are on that branch and will not be moving off it for weeks, and one said neither a Jumbo Hotfix nor a Live Patch existed for it, leaving mitigation as the only option [13]. The mitigation is turning off implied rules for VPN. One customer called that too vague to act on and asked which configuration lines to comment out; another asked how to apply it without affecting remote users; neither got an answer in the thread [14].
The June and July flaws in these same products were being exploited when Check Point announced them [17]. June's, CVE-2026-50751, was an authentication bypass in Remote Access VPN and Mobile Access certificate validation, and CISA added it to the Known Exploited Vulnerabilities catalog on June 8 [18]. July's, CVE-2026-16232, was a SmartConsole authentication bypass, and it went into the same catalog [19]. Counting this week's pair, that is four criticals in the line since June, two of them exploited before the vendor spoke [21], with 93 days between the June KEV entry and this disclosure [20]. This time the fix exists ahead of the attack traffic, which helps only on the gateways whose take level actually moves.
What to watch
- Whether CISA adds CVE-2026-85102 or CVE-2026-85103 to the KEV catalog, which would end the vendor-found-only read.
- Whether Check Point publishes fixed take numbers per branch rather than an affected-versions list.
- Whether an R81.10 route appears, or the implied-rules mitigation is written out as specific configuration lines.