$ techbeacon▋
CVE & Exploits

Check Point Flags Two Critical VPN Flaws That Permit Unauthenticated Remote Code Execution

Check Point Flags Two Critical VPN Flaws That Permit Unauthenticated Remote Code Execution

Check Point Software Technologies disclosed two high‑severity vulnerabilities in its VPN gateway software that could enable attackers without any credentials to execute arbitrary code on compromised devices. The flaws, catalogued as CVE‑2026‑85102 and CVE‑2026‑85103, affect the core remote‑access functionality used by enterprises worldwide.

Both issues stem from improper handling of specially crafted packets sent to the VPN service. Under certain configurations, the gateway fails to validate input before passing it to internal routines, creating a pathway for malicious code to run with system privileges. Successful exploitation could give an adversary full control over the affected security appliance, potentially allowing them to intercept traffic, alter configurations, or pivot deeper into a corporate network.

The vulnerabilities were initially reported by the independent security group GBHackers, who provided proof‑of‑concept samples that demonstrated remote code execution without requiring authentication. Check Point acknowledged the report and began internal testing, confirming the findings and assigning the CVE identifiers. The company has not disclosed the exact versions affected, but notes that the bugs are present in multiple releases of its gateway firmware that are still in active deployment.

Given the widespread adoption of Check Point's VPN solutions in large‑scale enterprises, data centers, and government agencies, the potential impact is significant. Unauthenticated access bypasses many of the traditional security layers that organizations rely on, and the ability to run code on a gateway could undermine the confidentiality and integrity of all traffic passing through the device. Analysts warn that threat actors could weaponize these flaws to establish persistent footholds in high‑value targets.

Check Point has issued emergency advisories urging customers to apply the forthcoming patches as soon as they become available. In the interim, the vendor recommends disabling the vulnerable services, restricting inbound VPN traffic to trusted IP ranges, and monitoring logs for anomalous connection attempts. The company also pledged to provide detailed mitigation guidance and to work with partners to accelerate the rollout of updates.

The disclosure adds to a growing list of recent VPN‑related security issues that have prompted heightened scrutiny of remote‑access infrastructure. Experts emphasize that timely patch management, layered network segmentation, and regular security assessments are essential to reduce exposure to similar zero‑day exploits. As organizations continue to rely on VPNs for remote work, the Check Point incident underscores the importance of proactive vulnerability management and rapid response to emerging threats.

Source: GBHackers
Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related