2026-012: Critical Vulnerabilities in Check Point Products
On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-Site VPN. Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances. CERT-EU strongly recommends applying the available hotfixes as soon as possible, prioritising internet-facing and perimeter appliances.
Details
Original advisory: https://cert.europa.eu/publications/security-advisories/2026-012/
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-85102 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-85103 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEU] [hoch] Check Point Security Gateway, Spark Firewall und Security Management: Mehrere Schwachstellen ermö…cert-bund
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN productenncsc-nl
- unknownCheck Point security advisory (AV26-902)cccs
- criticalCVE-2026-85103: A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated re…nvd
- criticalCVE-2026-85102: Improper certificate trust validation during VPN negotiation in Check Point Quantum Security G…nvd
Recent advisories for 2026-012
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalDrupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-012drupal · 2026-07-15
More from CERT-EU Security Advisories
- critical2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server2026-09-09
- critical2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway2026-08-19
- critical2026-009: Critical Vulnerabilities in Microsoft SharePoint2026-07-23
- critical2026-008: Critical vulnerabilities in Ivanti Sentry2026-06-10
- critical2026-007: Critical Vulnerability in Windows Netlogon2026-06-10