Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
Check Point has disclosed and patched two high-severity vulnerabilities in its network security infrastructure that could permit unauthenticated attackers to execute arbitrary code remotely. The flaws, rated with a CVSS score of 9.8, affect the processing of VPN certificates within the Security Gateway and Security Management Server components.
The first issue, tracked as CVE-2026-85102, involves improper validation of certificate trust during the VPN handshake process on Security Gateways. The second, identified as CVE-2026-85103, stems from a heap-based buffer overflow error occurring while decoding ASN.1 structures in VPN certificates; this bug impacts both Quantum Security Management and Quantum Security Gateway systems. While the company notes that no active exploitation has been observed, administrators are urged to apply the available hotfixes immediately.