Check Point VPN Bugs Expose Gateway Code Execution

NCSC-NL says Check Point fixed two critical VPN flaws, CVE-2026-85102 and CVE-2026-85103, in Quantum Security Gateway and Check Point Spark Firewall, and expects broad abuse soon. The bugs affect site-to-site and remote-access VPN use at the perimeter. One flaw is an improper certificate-trust check in VPN negotiation, which can let an unauthenticated attacker bypass authentication and run code on the gateway before the connection is established. The other is a heap-based buffer overflow in ASN.1 decoding of VPN certificates, where malformed certificate data can crash the decoder into executing attacker code. For organizations that put Check Point at the network edge, the exposure sits in the handshake itself: the device can be taken over through the very path meant to establish trust. Site-to-site deployments also inherit a wider attack surface where UDP/500 and UDP/4500 are exposed for VPN traffic.

Part of the PlainSec briefing for 2026-09-10

Editions

Sources