Check Point Discloses Flaws

Overview

Check Point has patched two critical VPN certificate vulnerabilities in its firewall and management products, both rated CVSS 9.8. The flaws could allow unauthenticated remote attackers to execute code under specific conditions, though Check Point has not detailed those conditions.

Vulnerability Details

  • CVE‑2026‑85102:
    • A failure to properly validate certificate trust during VPN negotiation.
    • Could allow unauthenticated attackers to run code on Security Gateways.
  • CVE‑2026‑85103:
    • Heap‑based buffer overflow during ASN.1 certificate decoding.
    • Could allow unauthenticated attackers to run code on Quantum Security Management and Quantum Security Gateway systems.

Both flaws affect:

  • R82.10 with Jumbo Hotfix Take 43 or below
  • R82 with Jumbo Hotfix Take 125 or below
  • R81.20 with Jumbo Hotfix Take 165 or below

Product Impact

  • Security Gateways
  • Security Management Server
  • Spark Firewall (including Site‑to‑Site and Remote Access VPN deployments)

Check Point confirmed the flaws were discovered internally and said there is no evidence of exploitation in the wild.

Patch & Mitigation Routes

  • Live Patch: Automatically protects customers as rollout begins (available for R81.20, R82.00, R82.10).
  • Jumbo Hotfix: Customers should install the latest hotfix for their deployed version.

For customers unable to patch immediately (e.g., R81.10 users), mitigation guidance includes disabling implied VPN rules, though community feedback suggests the instructions were vague.

Historical Context

  • CVE‑2026‑50751 (June): Authentication bypass in Remote Access VPN and Mobile Access certificate validation. Added to CISA’s KEV catalog.
  • CVE‑2026‑16232 (July): SmartConsole authentication bypass. Also added to KEV.
  • Both flaws were confirmed as actively exploited at disclosure.

Defensive Guidance

Organizations should:

  • Apply Live Patch or Jumbo Hotfix immediately.
  • Audit VPN certificate configurations for unexpected entries.
  • Remove public exposure of management interfaces.
  • Monitor logs for suspicious certificate processing activity.
  • Review Spark deployments to ensure patches or mitigations are applied.

Expert in the Cloud Insight

These flaws highlight how certificate handling in VPN infrastructure can become a critical attack vector. Even without evidence of exploitation, the CVSS 9.8 severity demands urgent action. The lesson is clear: patch quickly, monitor certificate trust paths, and restrict exposure of management consoles to trusted networks.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.