Check Point patches two VPN flaws that can enable unauthenticated RCE. It reports no exploitation.
CVE-2026-85102 combines authentication bypass with remote code execution; CVE-2026-85103 is an ASN.1 decoding heap overflow. Fixes are available through LivePatch and Jumbo Hotfix packages, but estates must verify that protection is actually armed.
By Parminder Kumar Sharma · · 3 min read

The vendor distinguishes two routes to remote code execution
Check Point’s security notice identifies two internally discovered VPN-related vulnerabilities. CVE-2026-85102 is an authentication bypass and remote-code-execution issue in Remote Access and Site-to-Site VPN. CVE-2026-85103 is a heap overflow in ASN.1 certificate decoding that can also lead to remote code execution.
Check Point says exploitation is possible without authentication under specific conditions. It also says it has no indication of active exploitation. Both statements matter: the potential impact is critical, while the current evidence does not justify claiming an observed campaign.
Authentication bypass and certificate parsing require separate checks
The first flaw concerns access controls in VPN functionality. The second concerns certificate processing, so asset teams should not assume a gateway is outside scope solely because ordinary remote-access use is limited.
The vendor’s detailed support advisories define affected products, conditions and packages. Administrators should map each gateway and management system to those records rather than applying one generic VPN label.
The two disclosed vulnerabilities
| CVE | Mechanism | Potential result |
|---|---|---|
| CVE-2026-85102 | Authentication bypass in Remote Access and Site-to-Site VPN | Unauthenticated remote code execution |
| CVE-2026-85103 | Heap overflow during ASN.1 certificate decoding | Unauthenticated remote code execution |
Live Patch reduces deployment time, but coverage still needs proof
Check Point initially said customers using Live Patch would receive automatic protection as the rollout beginning on 9 September reached their systems. In a later official response on the same advisory page, Check Point clarified that the fixes are available immediately: administrators can download the relevant LivePatch packages from the linked support articles or receive them through the automatic LivePatch mechanism. The fixes are also included in the applicable Jumbo Hotfix packages.
Availability is not fleet coverage. Inventory management servers and gateways, record release and hotfix levels, and verify that the relevant live patches are installed and armed on running processes. An enabled update mechanism or a downloaded package does not prove that every node and process is protected.
Where change windows delay a full package, restrict exposed services and management routes according to vendor guidance. Retain before-and-after evidence so a green console status does not substitute for a complete estate check.
The position
VPN infrastructure is an authentication boundary exposed to untrusted traffic, so unauthenticated code execution deserves emergency treatment even without a known campaign. The right wording is urgent without being sensational: critical potential impact, internally discovered, no active exploitation reported.
Teams should also use the event to test whether their asset system can answer a precise question quickly: which gateways process the affected VPN or certificate paths, and which protection is running on each one?
Sources
- PrimaryCritical Security Advisory: VPN VulnerabilitiesCheck Point CheckMatesaccessed 2026-09-13


