Free delivery

GGuestNot signed in
You're not signed in
LoginCreate account

9/11/2026 • Security

Check Point VPN Flaws: Two 9.8s, and a Fix That Installs Itself

Check Point has disclosed two CVSS 9.8 flaws in how its Quantum Security Gateways and Quantum Spark firewalls handle VPN certificates, exploitable with no login. Fixes shipped the same day, and for many customers they installed automatically. Whether yours did depends on one setting.

Two vulnerabilities in Check Point's firewalls each scored a near-perfect CVSS 9.8 this week, and both can be triggered by an attacker who has never logged in. On 9 September 2026 Check Point published advisories for CVE-2026-85102 and CVE-2026-85103, a pair of flaws in how its Quantum Security Gateways and Quantum Spark firewalls handle certificates during VPN negotiation. The unusual part of this story is not the severity. It is that the fixes shipped the same day, and for customers who had left one setting switched on, the patch installed itself before most people had read the headline.

If your business runs a Check Point gateway or a Quantum Spark appliance with any kind of VPN, this one is worth ten minutes today.

What happened, in plain English

Both flaws live in the code that processes the digital certificate a remote peer presents when it tries to set up a VPN tunnel. That is a step that happens before anyone is authenticated, which is exactly why these bugs are so serious.

  • CVE-2026-85102 is an improper certificate trust validation flaw (CWE-295). The gateway does not properly check whether it should trust the certificate it has been handed. An unauthenticated remote attacker can push the VPN negotiation far enough to run their own code on the Security Gateway. Check Point tracks this as advisory sk1000117.
  • CVE-2026-85103 is a heap-based buffer overflow (CWE-122) in the ASN.1 decoder that parses the certificate's structure. A malformed certificate can trigger it, again with no credentials, and again leading to code execution. This one also reaches the Security Management Server, not just the gateway. Check Point tracks it as sk1000118.

The honest nuances, because they matter:

  • Genuinely unauthenticated. The NVD vector for both flaws is network-reachable, low complexity, no privileges, no user interaction. This is the real thing, not a "critical" that quietly needs an admin password first.
  • Not known to be exploited. Check Point's own research team found both flaws internally. As of 11 September neither CVE is on CISA's Known Exploited Vulnerabilities catalogue, and Check Point has reported no evidence of in-the-wild attacks or public proof-of-concept code. That could change. Flaws this severe in internet-facing VPN code tend to attract attention quickly once the fix is public, because the patch itself tells researchers where to look.
  • Patches exist, and R82.20 was never affected.

Affected versions. Security Gateway releases R81.20, R82 and R82.10 with Jumbo Hotfix takes below the fixed builds. The older R80.x, R81 and R81.10 branches are also affected but are end of support, so they will not receive a fix. On the Quantum Spark side, the small-business line, the R81.10.x and R82.00.x firmware families are affected, both centrally and locally managed.

The fix. Check Point delivered it three ways:

  1. LivePatch. If automatic LivePatch installation is enabled, the protection was applied automatically from 9 September. Check Point's advisory shows how to confirm it: the LivePatch bundle should report Take 24, and the cplp list output should name both CVEs.
  2. Jumbo Hotfix Accumulator. R82.10 Take 44 or later, R82 Take 126 or later, R81.20 Take 166 or later.
  3. Spark firmware. R82.00.10 build 2325 or later, or R81.10.17 build 4968 or later.

There is also a partial mitigation for site-to-site VPN only: turn off the implied rules for VPN and manually allow UDP 500 and UDP 4500 from your specific peer addresses. Check Point notes this does not apply to locally managed Spark firewalls, and it does nothing for remote-access VPN, where by definition your users connect from anywhere.

Why this one matters: the fix is only as good as the switch

Last week we wrote about SonicWall SMA 1000 zero-days that were exploited before a patch existed. This is the mirror image. Here the vendor found the bugs, built the fix, and pushed it out on day one. Done right, that is what good vulnerability handling looks like, and Check Point deserves credit for it.

But notice where the responsibility lands. If LivePatch automatic installation was enabled, you were protected without lifting a finger. If it was not, your gateway is still vulnerable right now, and the only thing separating those two outcomes is a setting someone chose, or never got round to choosing, months or years ago.

That is the real lesson for a small business. The security of your network edge increasingly depends less on how vigilant you are on any given Tuesday and more on whether you have set things up so that fixes arrive without you. VPN gateways sit on the public internet by design, they are the device most worth attacking, and they are usually the device nobody looks at until something breaks. Automatic patching is how you stop relying on memory.

The second lesson is about end-of-support gear. Anyone still on R80.40 or R81 has a perfect-score, no-login flaw and no fix coming. We have covered where that road leads before, and it does not improve with time.

The honest bit

No vendor is immune, including the ones we like. We sell Cisco and Meraki equipment, and Cisco has had its own run of advisories in this very series. Certificate parsing and VPN negotiation code is complicated, it runs before authentication, and every firewall vendor on the market has shipped bugs in it at some point. Check Point is not the villain here. If anything, finding your own flaws and patching them on disclosure day is the behaviour we want to see more of.

One genuine difference worth stating as advice rather than a pitch: cloud-managed platforms make the "fixes arrive without you" model the default rather than an opt-in. Firmware is pushed on a schedule the vendor controls, and end-of-support dates are published so you can plan a refresh instead of discovering it from an advisory. We have written about why that model keeps improving after you buy it. Check Point's LivePatch is the same idea for its own platform. Whatever brand you run, the goal is identical: make automatic the thing you would otherwise have to remember.

What we'd suggest you actually do

  1. Find out if you run affected gear. Any Check Point Security Gateway on R81.20, R82 or R82.10, any Quantum Spark on R81.10.x or R82.00.x firmware, and any Security Management Server on those releases. If you use site-to-site or remote-access VPN on it, treat it as exposed.
  2. Check whether LivePatch already fixed it. In Expert mode on the gateway, confirm the urgent security bundle is at Take 24 and that cplp list shows both CVE numbers. If it does, you are done for this one.
  3. If not, patch now. Apply the Jumbo Hotfix for your release, or the Spark firmware build listed above. If you cannot patch immediately and only use site-to-site VPN, apply the implied-rules mitigation as a stopgap, but do not treat it as the fix.
  4. Turn automatic LivePatch on if it was off. This is the setting that would have made this week a non-event.
  5. If you are on an end-of-support release, there is no patch. Upgrade to a supported release, or plan the replacement. A CVSS 9.8 with no login and no fix is not a device to leave facing the internet.
  6. Do the basics on every edge device. Management interfaces off the public internet, unique admin credentials, multi-factor authentication where the platform supports it, and a subscription to your vendor's security advisories so news like this reaches you the day it lands.

The friendly takeaway

This was, by the standards of the industry, a well-handled disclosure: vendor-found, fixed on day one, pushed automatically to anyone who had let it. The uncomfortable bit is that "anyone who had let it" is the whole story. Two perfect-score flaws in the front door of your network were either closed before you heard about them, or are still open now, and the difference is a setting.

As always, this post is part of us keeping watch so you don't have to. If you would like a second pair of eyes over your network edge, whether it is Check Point, Cisco, Meraki, or something you inherited and are not sure about, get in touch. No obligation, no hard sell. Sometimes a quick look at what is exposed and what is patching itself is all it takes.

References

Contact Us

Email: [email protected]

Phone: 1300 989 334

About

Your one-stop technology hub for all your networking, security, and IT needs. From cutting-edge networking solutions to robust security products, we provide everything your business requires to stay connected, secure, and efficient. Whether you're looking for advanced hardware, software, or services, we offer reliable, innovative technology tailored to help you build and protect your digital infrastructure.

Copyright © 2026 TYONLINE TECHNOLOGY PTY. LTD. All Rights Reserved.