A critical vulnerability regarding VPN certificate processing has been identified in Check Point products:
- CVE-2026-85102 (CVSS 9.8)
This vulnerability stems from a flaw in certificate data validation during VPN connection establishment, which could allow an unauthenticated remote attacker to execute arbitrary code on the Security Gateway device.
Affected devices include Check Point Security Gateway and Check Point Spark Firewall using Site-to-Site or Remote Access VPN.
Affected versions:
- 20, R82, R82.10
- End-of-Support (EoS) versions: R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10
- x, R82.00.x
Version R82.20 is not affected, while patches are available via Check Point LivePatch and Jumbo Hotfix Accumulator, as well as through the corresponding versions for Spark Firewall devices.
CVE-2026-93616 (new)
A zero-day vulnerability, CVE-2026-93616 (CVSS 9.8) has been discovered in the Check Point Management web service. This vulnerability can be exploited without prior authentication. It allows an attacker to execute a script from an arbitrary path and load an arbitrary Java class. Check Point Research has identified a small number of targeted attacks in which this vulnerability was exploited.
Affected products: Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, SmartEvent.
Affected versions:
- 20
- 10 Jumbo Hotfix Take 44 or lower
- R82 Jumbo Hotfix Take 126 or lower
- 20 Jumbo Hotfix Take 166 or lower
- End-of-Support (EoS) versions: R81.10 Jumbo Hotfix Take 190 or lower, R80, R80.10, R80.20, R80.30, R80.40, R81
The National CERT recommendations are:
For CVE-2026-85102
- apply the appropriate fix (LivePatch or Jumbo Hotfix Accumulator, depending on the version) or update Spark Firewall devices to the appropriate patched versions;
- if an update cannot be performed immediately, apply the workaround specified in the vendor's advisory (the workaround is not applicable to locally managed Spark Firewalls);
- For End-of-Support (EoS) versions, consider migrating to a supported version.
For CVE-2026-93616
- apply the appropriate fix;
- if an update cannot be performed immediately, apply the workarounds specified in the vendor's advisory;
- for proactive searching for Indicators of Compromise (IoC), consult document sk1000171.
Note: Check Point LivePatch Take 28/29 does not remediate this vulnerability.
More details at: