Key Facts

Check Point has released fixes for CVE-2026-85102 and CVE-2026-85103, two critical VPN-certificate vulnerabilities. The Hacker News reports that Check Point assigned both a CVSS score of 9.8 and said it has no indication either issue has been used in attacks.

Technical Details

CVE-2026-85102 concerns certificate-trust validation during VPN negotiation on Security Gateways. CVE-2026-85103 is a heap-based buffer overflow while decoding a VPN-certificate ASN.1 structure and affects Quantum Security Management and Quantum Security Gateway systems, according to the published advisories.

Impact & Mitigation

Apply Check Point Live Patch where available or install the latest applicable Jumbo Hotfix. Check Point’s customer notice directs users to its advisories for mitigation and remediation guidance; prioritize internet-exposed security gateways and management systems.

Sources

By Allan