Critical Vulnerabilities in Check Point Security Appliances
Check Point has disclosed critical vulnerabilities, including CVE-2026-85102 and CVE-2026-85103, affecting various Security Gateway, Management Server, and Spark Firewall deployments.
CVE search metadata
CVE search record: CVE-2026-85102. Severity: critical. CVSS: 9.8. KEV: no. Product: Security Gateway, Spark Firewall, Security Management Server. Brief: Critical Vulnerabilities in Check Point Security Appliances. Brief link: https://feed.craftedsignal.io/briefs/2026-09-checkpoint-vulnerabilities/
CVE search record: CVE-2026-85103. Severity: critical. CVSS: 9.8. KEV: no. Product: Security Gateway, Spark Firewall, Security Management Server. Brief: Critical Vulnerabilities in Check Point Security Appliances. Brief link: https://feed.craftedsignal.io/briefs/2026-09-checkpoint-vulnerabilities/
On September 9, 2026, Check Point released security advisories identifying multiple critical vulnerabilities across its product line, specifically impacting Security Gateway, Security Management Server, and Spark Firewall appliances. The flaws include CVE-2026-85102, which allows for authentication bypass and remote code execution (RCE) via Site-to-Site or Remote Access VPN configurations, and CVE-2026-85103, a heap overflow vulnerability in ASN.1 decoding that also facilitates RCE. These vulnerabilities present significant risks to enterprise perimeter security, as successful exploitation could grant attackers unauthorized access to internal networks or complete control over the affected appliances. Defenders should prioritize patching and monitor for unusual traffic patterns associated with VPN termination points and ASN.1 processing services.
Impact
Successful exploitation of these vulnerabilities allows unauthenticated attackers to achieve remote code execution on internet-facing Check Point infrastructure. This impact could lead to full system compromise, exfiltration of sensitive configuration data, lateral movement into protected internal network segments, and long-term persistence within the target organization's security boundary.
Recommendation
- Apply vendor-supplied security patches or updates for Security Gateway, Security Management Server, and Spark Firewall as documented in the Check Point support articles linked below.
- Monitor firewall and VPN logs for anomalous authentication attempts or unexpected process crashes that may indicate exploitation attempts (CVE-2026-85102, CVE-2026-85103).
- Ensure management interfaces are isolated from the public internet and restricted to authorized management subnets.
Immediate actions
Apply recommended firmware updates for all Check Point Security Gateway, Spark Firewall, and Management Server instances.
Mitigations
Restrict access to VPN and management interfaces to known trusted IP ranges until patches are verified.
CVE-2026-85102