{
    "file_item": {
        "filepath": "security-advisories",
        "filename": "CERT-EU-SA2026-012.pdf"
    },
    "title": "Critical Vulnerabilities in Check Point Products",
    "serial_number": "2026-012",
    "publish_date": "10-09-2026 08:20:06",
    "description": "On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-Site VPN. Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances.<br>\nCERT-EU strongly recommends applying the available hotfixes as soon as possible, prioritising internet-facing and perimeter appliances.<br>\n",
    "url_title": "2026-012",
    "content_markdown": "---\ntitle: 'Critical Vulnerabilities in\u00a0Check\u00a0Point\u00a0Products'\nnumber: '2026-012'\nversion: '1.0'\noriginal_date: '2026-09-09'\ndate: '2026-09-10'\n---\n\n_History:_\n\n* _10/09/2026 --- v1.0 -- Initial publication_\n\n# Summary\n\nOn 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting **Check Point Security Gateway**, **Security Management Server**, and **Spark Firewall** deployments configured to use Remote Access VPN or Site-to-Site VPN [1,2]. Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances [1,2].\n\nCERT-EU strongly recommends applying the available hotfixes as soon as possible, prioritising internet-facing and perimeter appliances.\n\n# Technical Details\n\nThe vulnerability **CVE-2026-85102**, with a CVSS score of 9.8, is an **improper certificate-data validation vulnerability** in the VPN negotiation flow of Check Point Security Gateway that allows an unauthenticated, remote attacker to execute arbitrary code on the affected appliance [1]. The issue affects deployments using either Site-to-Site VPN or Remote Access VPN [1].\n\nThe vulnerability **CVE-2026-85103**, with a CVSS score of 9.8, is a **heap overflow vulnerability** in the VPN certificate ASN.1 decoding flow of Check Point Security Gateway and Security Management Server that allows a remote attacker to execute arbitrary code on the affected appliance [2]. Unlike **CVE-2026-85102**, this vulnerability affects both the Security Gateway and the Security Management Server [2].\n\n# Affected Products\n\nThe following Check Point products and versions are affected [1,2]:\n\n- Check Point Security Gateway \u2014 R80, R80.10, R80.20, R80.30, R80.40 (End of Support)\n- Check Point Security Gateway \u2014 R81, R81.10 (End of Support)\n- Check Point Security Gateway \u2014 R81.10.X\n- Check Point Security Gateway \u2014 R81.20\n- Check Point Security Gateway \u2014 R82\n- Check Point Security Gateway \u2014 R82.00.X\n- Check Point Security Gateway \u2014 R82.10\n- Check Point Security Management Server \u2014 all versions listed above\n- Check Point Spark Firewall (Centrally Managed and Locally Managed) \u2014 all versions listed above\n\nExploitation of **CVE-2026-85102** requires the deployment to be configured with either Remote Access VPN or Site-to-Site VPN [1]. Exploitation of **CVE-2026-85103** additionally affects the Security Management Server in such configurations [2].\n\nAdditional information is available in the vendor's advisories [1,2].\n\n# Recommendations\n\nCERT-EU strongly recommends that all organisations running affected Check Point products apply the available hotfixes immediately [1].\n\n# References\n\n[1] <https://support.checkpoint.com/results/sk/sk1000117/>\n\n[2] <https://support.checkpoint.com/results/sk/sk1000118/>\n",
    "content_html": "<p><em>History:</em></p><ul><li><em>10/09/2026 --- v1.0 -- Initial publication</em></li></ul><h2 id=\"summary\">Summary</h2><p>On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting <strong>Check Point Security Gateway</strong>, <strong>Security Management Server</strong>, and <strong>Spark Firewall</strong> deployments configured to use Remote Access VPN or Site-to-Site VPN [1,2]. Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances [1,2].</p><p>CERT-EU strongly recommends applying the available hotfixes as soon as possible, prioritising internet-facing and perimeter appliances.</p><h2 id=\"technical-details\">Technical Details</h2><p>The vulnerability <strong>CVE-2026-85102</strong>, with a CVSS score of 9.8, is an <strong>improper certificate-data validation vulnerability</strong> in the VPN negotiation flow of Check Point Security Gateway that allows an unauthenticated, remote attacker to execute arbitrary code on the affected appliance [1]. The issue affects deployments using either Site-to-Site VPN or Remote Access VPN [1].</p><p>The vulnerability <strong>CVE-2026-85103</strong>, with a CVSS score of 9.8, is a <strong>heap overflow vulnerability</strong> in the VPN certificate ASN.1 decoding flow of Check Point Security Gateway and Security Management Server that allows a remote attacker to execute arbitrary code on the affected appliance [2]. Unlike <strong>CVE-2026-85102</strong>, this vulnerability affects both the Security Gateway and the Security Management Server [2].</p><h2 id=\"affected-products\">Affected Products</h2><p>The following Check Point products and versions are affected [1,2]:</p><ul><li>Check Point Security Gateway \u2014 R80, R80.10, R80.20, R80.30, R80.40 (End of Support)</li><li>Check Point Security Gateway \u2014 R81, R81.10 (End of Support)</li><li>Check Point Security Gateway \u2014 R81.10.X</li><li>Check Point Security Gateway \u2014 R81.20</li><li>Check Point Security Gateway \u2014 R82</li><li>Check Point Security Gateway \u2014 R82.00.X</li><li>Check Point Security Gateway \u2014 R82.10</li><li>Check Point Security Management Server \u2014 all versions listed above</li><li>Check Point Spark Firewall (Centrally Managed and Locally Managed) \u2014 all versions listed above</li></ul><p>Exploitation of <strong>CVE-2026-85102</strong> requires the deployment to be configured with either Remote Access VPN or Site-to-Site VPN [1]. Exploitation of <strong>CVE-2026-85103</strong> additionally affects the Security Management Server in such configurations [2].</p><p>Additional information is available in the vendor's advisories [1,2].</p><h2 id=\"recommendations\">Recommendations</h2><p>CERT-EU strongly recommends that all organisations running affected Check Point products apply the available hotfixes immediately [1].</p><h2 id=\"references\">References</h2><p>[1] <a rel=\"noopener\" target=\"_blank\" href=\"https://support.checkpoint.com/results/sk/sk1000117/\">https://support.checkpoint.com/results/sk/sk1000117/</a></p><p>[2] <a rel=\"noopener\" target=\"_blank\" href=\"https://support.checkpoint.com/results/sk/sk1000118/\">https://support.checkpoint.com/results/sk/sk1000118/</a></p>",
    "licence": {
        "title": "Creative Commons Attribution 4.0 International (CC-BY 4.0)",
        "link": "https://creativecommons.org/licenses/by/4.0/",
        "restrictions": "https://cert.europa.eu/legal-notice",
        "author": "The Cybersecurity Service for the Union institutions, bodies, offices and agencies"
    }
}