Check Point CVE-2026-85102 / 85103: Two 9.8 VPN Flaws with Unauthenticated RCE, Exploitation Called Imminent
> TL;DR: On September 9, 2026, Check Point fixed two critical vulnerabilities in how its firewalls and management consoles handle VPN certificates. CVE-2026-85102 (CVSS 9.8) is a failure to properly validate certificate trust during VPN negotiation, potentially enabling unauthenticated remote code execution on Security Gateways. CVE-2026-85103 (CVSS 9.8) is a heap-based buffer overflow while decoding a certificate's ASN.1 structure, affecting Quantum Security Management and Quantum Security Gateway systems. Check Point, which found both flaws internally, says it has no evidence of exploitation — but the Dutch NCSC warns exploitation is imminent. Affected versions: R82.10 (JHF Take 43 and below), R82 (Take 125 and below), R81.20 (Take 165 and below).
The mechanism: the certificate as attack surface
Both flaws trigger during certificate processing — attacker-controlled input in VPN flows. The first breaks trust validation (a malicious certificate passes as legitimate, with potential code execution on the gateway); the second corrupts memory during ASN.1 decoding (heap overflow, same outcome). Two important Check Point clarifications:
The vendor's context presses: in June, CVE-2026-50751 (Remote Access VPN authentication bypass) was already exploited at disclosure (KEV June 8); in July, CVE-2026-16232 (SmartConsole) was KEV'd the same day. Check Point VPN flaws have a history: they convert into access fast.
The editorial response blind spots
The case also offers operational lessons, reported by customers on the community forum: R81.10 branches with no patch path (mitigation only, described as too vague to apply), a progressive Live Patch rollout that had not reached all appliances days after the announcement, broken download links, and no published IoCs — logical, since no public exploit exists yet. For your teams: do not assume the fix is applied because it is available; verify the effective version on every appliance, including secondary lines (Spark, management).
What to do
The broader lesson
Firewalls and VPN concentrators are the most systematically converted initial-access category of the past three years (Ivanti, Fortinet, Palo Alto, Citrix, SonicWall, and now Check Point repeatedly). The reason is structural: they are exposed by function, they process unauthenticated input (certificates, handshakes), and compromising them delivers the inside of the network. Two consequences for every organization: their patch cycle must be the shortest in the estate (hours, not weeks), and the assumption "the VPN may be compromised" must exist in the architecture — segmentation behind the gateway, MFA on internal resources, monitoring of accounts transiting through it.
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
PaperCut NG/MF: Two Zero-Days Chained for Unauthenticated RCE, Incomplete Patches, and a CISA Deadline
Flaws in the PaperCut NG and MF print management software are exploited in real attacks: an authentication bypass (CVE-2026-81578) followed by unsafe dynamic class loading (CVE-2026-82078) leads to arbitrary Java code execution without an account. Two successive emergency patches, patch bypasses already identified against the latest fully patched version, and a CISA KEV entry with a September 14, 2026 deadline.
ServiceNow: Three CVSS 10.0 Flaws Including a GraphQL Injection — Self-Hosted Instances Must Patch Themselves
Four vulnerabilities fixed on August 27, 2026 in the ServiceNow platform, three of them rated 10.0: code injection in the GraphQL Composite Data API (CVE-2026-18885), broken access control in the configuration image upload processor (CVE-2026-18886), SQL injection via a dynamic ORDER BY (CVE-2026-74820), plus a sandbox escape (CVE-2026-6876). ServiceNow-hosted instances are already protected.
Cisco FMC CVE-2026-20079: Three Attacker Clusters, from Web Shells to Qilin Ransomware via Sandworm
Cisco Talos documents three clusters exploiting patched Secure Firewall Management Center flaws: CVE-2026-20079 (CVSS 10.0 auth bypass leading to root) and CVE-2026-20316 (5.3 low-privilege access as entry). Web shells and credential theft, a Cyclops Blink implant linked to Sandworm, and a full Qilin deployment through legitimate FMC tooling. KEV deadline: September 12.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.