Check Point Issues Emergency Patch for Two Critical VPN Flaws
Check Point Software Technologies announced the release of emergency updates to address two high‑severity vulnerabilities discovered in its VPN gateway products, identified as CVE-2026-85102 and CVE-2026-85103. Security researchers disclosed that both flaws could allow an unauthenticated attacker to execute arbitrary code on affected devices, potentially giving the attacker full control of corporate networks that rely on the company's remote‑access solutions.
The vulnerabilities stem from improper handling of crafted network packets that traverse the VPN tunnel. In the case of CVE-2026-85102, the flaw lies in the parsing routine for inbound traffic, while CVE-2026-85103 involves a buffer‑overflow condition in the authentication module. Exploitation of either issue would enable remote code execution without requiring valid credentials, a scenario that security experts consider “critical” because it bypasses the primary defense that VPNs are meant to provide.
Check Point’s response, detailed in a security advisory posted on its website, urges all customers to apply the supplied patches immediately. The company has also released updated firmware versions for its popular Check Point Remote Access VPN appliances and provided guidance on verifying successful installation. For organizations that cannot patch right away, temporary mitigations such as disabling the vulnerable services or restricting inbound traffic to trusted IP ranges are recommended.
The disclosure follows a broader trend of attackers targeting VPN infrastructure, a vector that has gained prominence as remote work continues to expand. Industry analysts note that VPN appliances are attractive because they sit at the network perimeter and often have privileged access to internal resources. The rapid patch cycle demonstrated by Check Point reflects the heightened pressure on vendors to address such threats quickly, especially after high‑profile incidents involving similar remote‑code‑execution bugs in other vendors' products.
SecurityWeek, which first reported the issue, highlighted that the CVE identifiers were assigned in early September 2026, suggesting that the vulnerabilities were discovered and reported to Check Point in a coordinated fashion. The vendor’s prompt issuance of patches aligns with best practices for responsible disclosure, allowing customers to remediate before public exploit code becomes widely available. As organizations begin rolling out the updates, cybersecurity teams are advised to monitor for any signs of attempted exploitation and to review their incident‑response playbooks for VPN‑related incidents.
Comments (0)
Be the first to comment.
Join the discussion