A rack-mounted firewall appliance lit in a darkened room
01
Threat Intel

Two Critical Vulnerabilities in Check Point Firewalls, and How to Proactively Defend Against Them

Speculus Threat Research Team·Sep 10, 2026·7 min read

Check Point identified and patched two critical unauthenticated RCEs internally. These vulnerabilities aren’t always discovered internally. Security teams need to be prepared to detect and stop these types of attacks.

What happened

On September 9, Check Point disclosed two critical vulnerabilities in the way its firewall and management products process VPN certificates, and began shipping fixes the same day. The company found both internally and says it has no indication either has been used in an attack.

CVE-2026-85102

CVSS 9.8 · Security Gateway

A failure to properly validate certificate trust during VPN negotiation. An unauthenticated remote attacker may be able to run code on the gateway.

CVE-2026-85103

CVSS 9.8 · Gateway + Management

A heap-based buffer overflow triggered while decoding the ASN.1 structure of a VPN certificate. Reaches Quantum Security Management as well as the gateway.

Check Point marks R82.10 (Jumbo Hotfix Take 43 or below), R82 (Take 125 or below), and R81.20 (Take 165 or below) as affected. Canada’s Cyber Centre published a broader product list the same evening, adding the Spark small-business firewall line, but no version information at all. Check Point says both flaws require “specific conditions” it has not described. As of yet, our team has identified no PoCs in the wild. This may be subject to change, and security teams need to be prepared.

The attack, at a high level

You do not need to read the patch to understand the shape of this. A VPN gateway’s job is to talk to strangers. Before anyone proves who they are, the device has to accept an inbound connection, read a certificate it has never seen, parse it, and decide whether to trust it or not.

That parsing happens before authentication, because parsing is how authentication gets decided. So a bug in the parser is reachable by anyone who can reach the port. In the first flaw (CVE-2026-85102) the gateway fails to validate trust correctly during the certificate negotiation. In the second (CVE-2026-85103), a malformed certificate structure overflows a heap buffer while being decoded. Both yield the same result: RCE on a device that is the defensive frontier of your network and is trusted by your devices.

Why patching alone will not carry you

You should patch your devices. But look at what customers reported in Check Point’s own community thread on day one, because it is a realistic picture of what an emergency patch cycle looks like inside a real organisation.

It’s natural to have a window between disclosure and the moment security teams patch their devices, and where you have no IOCs, you need to detect anomalous connections hitting your firewalls.

How to defend against this class of attack

01

Yes we will say it again: Patch

Install the latest Jumbo Hotfix for your deployed version. Check Point named R81.20, R82.00 and R82.10 for that route, and says it installs on top of any Jumbo level in those branches. Then confirm the take actually installed on every gateway, individually.

02

Forward your logs off the device, preferably to a security platform

This is the step people skip and regret. Logs that live only on the appliance are logs an attacker with code execution on that appliance controls and can delete. Ship gateway and management-server logs to a central platform in real time, retain them for months (not 30 days).

With no indicators of compromise published, retrospective hunting is the only way you will ever figure out if you were at one point affected by vulnerabilities of this nature, and you can only hunt data you kept.

03

Watch network activity for anomalous connections (Speculus)

A vulnerability of this nature does not produce failed logins, and stealthy attackers don’t leave remnants of malware droppers on the system. What it produces is a connection that should not exist: your VPN gateway reaching outbound to an address that is net new and found being distributed by a residential proxy provider, or an appliance starting to talk to internal hosts it never spoke to before.

This is where Speculus comes in. We do the hard work for you and give you extremely precise, near real time network threat intelligence data classifying IPs to malware campaigns, residential proxies, anonymizing VPNs, and fraudulent ISPs. The result is an instant classification on an IP: what activity has it conducted recently, where else it has appeared, and a summary that gives your security team the confidence to act fast.

The takeaway

Adversaries and security teams will continue to find vulnerabilities in Firewall appliances. Security teams need to position themselves to be able to detect, respond, and stop novel attacks.

What closes the gap is being proactive. This means having several layers of security and observability: updates applied and verified, logs that survive the compromise of the thing generating them, and behavioural visibility that works when there is nothing to signature. Check Point points customers to advisories sk1000117 and sk1000118 for affected products and remediation steps.

If your organization is looking to trial Speculus and our capabilities, our team will be more than happy to assist.

Contact us →