At a glance:
-
Check Point recently disclosed and patched two critical vulnerabilities (CVSS: 9.8) affecting Quantum Security Gateway, Security Management Server, and Spark Firewall products.
-
The vulnerabilities affect VPN certificate-processing functionality used by systems that provide remote access, site-to-site connectivity, and centralized security management.
-
The disclosure comes after two earlier Check Point vulnerabilities were added to CISA’s KEV catalog after active exploitation. Review affected deployments and verify that the latest vendor updates have been applied.
Threat summary
On September 9, 2026, Check Point, a network security vendor, disclosed two critical vulnerabilities affecting VPN certificate-processing functionality.
The vulnerabilities affect multiple versions of:
-
Quantum Security Gateway, the company's firewall and VPN platform
-
Security Management Server, which centrally manages Check Point environments
-
Spark Firewall products
These products are commonly deployed at the network perimeter to provide remote access, secure site-to-site connectivity, and centralized security administration. As part of establishing VPN connections, they validate and process digital certificates presented by external systems. The disclosed vulnerabilities affect that certificate validation and processing functionality.
The vulnerabilities both carry CVSS scores of 9.8:
-
CVE-2026-85102 is an improper certificate trust-validation issue during VPN negotiation. The CVE description states that an unauthenticated remote threat actor may be able to execute code on an affected Security Gateway under specific conditions.
-
CVE-2026-85103 is a heap-based buffer overflow in the code that processes VPN certificates. The vulnerability occurs while decoding ASN.1, the standard format used to store information within digital certificates. A specially crafted certificate may corrupt memory during processing and, under specific conditions, may lead to code execution on affected Security Gateway and Security Management Server systems.
Both flaws are reachable during certificate processing before VPN authentication is completed. Check Point reported that it discovered the vulnerabilities internally and began releasing fixes through Live Patch and updated Jumbo Hotfix packages on September 9, 2026.
Analysis
The affected products are commonly deployed at the network perimeter to provide remote access and site-to-site connectivity. As part of normal operations, these systems process traffic from external users, partners, and branch locations, placing the vulnerable certificate-processing functionality in systems that are routinely exposed to untrusted network traffic.
The impact of a successful compromise could extend beyond a single device. Security Gateway appliances control access to protected network resources, while Security Management Server systems manage security policies across multiple Check Point deployments. In environments where management servers are affected, administrative control over multiple managed devices may also be impacted. The extent of impact depends on how the affected systems are deployed and integrated within the organization.
Organizations running affected releases of VPN-enabled Security Gateway systems and Security Management Server deployments are the most relevant candidates for assessment because the disclosed vulnerabilities affect VPN certificate-processing functionality. Reviewing where VPN services and certificate-based communications are used will help determine exposure within the environment.
Earlier in 2026, CVE-2026-50751, a VPN authentication bypass, and CVE-2026-16232, a SmartConsole authentication bypass, were both added to the Known Exploited Vulnerabilities catalog after exploitation was identified. Notably, CVE-2026-16232 was one of three vulnerabilities disclosed by Check Point in July 2026, two of which affected Security Management Server, a component now affected by CVE-2026-85103.
Mitigations
Review Check Point Quantum Security Gateway, Security Management Server, and affected Spark Firewall deployments to determine which systems process VPN certificate traffic and require updates.
Install the latest vendor updates or verify that Check Point Live Patch protection is active to remove the vulnerable certificate-validation and certificate-parsing functionality from affected systems.
Where upgrades are pending, limit UDP ports 500 and 4500 to known VPN peers to reduce opportunities for untrusted systems to initiate VPN certificate exchanges with affected devices.
Monitor VPN logs for unusual negotiation attempts, certificate validation failures, parsing errors, or unexpected service crashes because both vulnerabilities are reached during certificate handling rather than through normal authenticated administration.
Review VPN certificates, trusted peers, and administrative accounts that are no longer required to reduce the number of systems and identities with access to security infrastructure. This hardening step does not address the vulnerabilities directly but can limit follow-on access if a device is compromised.
Disable unused VPN services and remove unnecessary internet exposure wherever possible to reduce the number of external systems capable of reaching the affected certificate-processing functions.