CODERED VTA

Check Point VPN Critical Flaws Allow Remote Code Execution on Enterprise Gateways

High
Check Point VPN Critical Flaws Allow Remote Code Execution on Enterprise Gateways
Image from Unsplash

Check Point has disclosed two critical vulnerabilities in its VPN infrastructure, tracked as CVE-2026-85102 and CVE-2026-85103, that could enable attackers to execute arbitrary code remotely on affected systems. Both flaws carry a vendor CVSS score of 9.8 and impact Check Point VPN products widely deployed across enterprise networks for secure remote access, including Security Gateway, Spark Firewall, and the Security Management Server. Organizations relying on Check Point VPN solutions face potential compromise of their perimeter security controls, which serve as critical gatekeepers for remote workforce connectivity and site-to-site communications.

Both vulnerabilities enable remote code execution, meaning an attacker could gain control over vulnerable VPN gateways without requiring prior authentication or user interaction. The two issues are certificate-related: CVE-2026-85102 is an improper validation of certificate data during VPN negotiation, while CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoding flow. Affected releases span R81.20, R82, and R82.10, as well as several end-of-support versions including R80.40 and R81. Remote code execution flaws in VPN infrastructure are particularly dangerous because these devices sit at the network perimeter, handle authentication credentials, and route sensitive traffic between remote users and internal resources.

Successful exploitation could allow attackers to intercept VPN traffic, harvest credentials, pivot into internal networks, or use compromised gateways as persistent footholds for lateral movement, because VPN gateways process authentication for remote workers, handle encrypted tunnels containing sensitive corporate data, and often maintain trust relationships with internal directory services. Check Point discovered both vulnerabilities internally and states there is currently no evidence of exploitation in the wild and no public proof-of-concept code, keeping present exploitation likelihood low. Nonetheless, the critical nature of the flaws and their unauthenticated remote code execution potential make them attractive targets for advanced persistent threat actors and ransomware operators seeking initial access; Check Point has released patches for both, and the exposure window depends entirely on patch-deployment velocity across distributed VPN infrastructure.

Attack Surface

Remote Access Service, Infrastructure

Tactics

Initial Access, Execution, Credential Access, Lateral Movement

Techniques

  • T1190 – Exploit Public-Facing Application
  • T1133 – External Remote Services
  • T1210 – Exploitation of Remote Services
  • T1557 – Adversary-in-the-Middle

SuperPRO's Threat Countermeasures Procedures

  1. Apply Check Point security patches for CVE-2026-85102 and CVE-2026-85103 immediately to all VPN gateway appliances and software installations
  2. Verify patch deployment by checking VPN gateway software versions against Check Point advisory guidance for the specific product line in use
  3. Restrict VPN gateway management interfaces to trusted IP ranges only, blocking public internet access to administrative consoles and APIs
  4. Enable logging for all VPN authentication attempts, configuration changes, and administrative access events with forwarding to centralized SIEM
  5. Monitor VPN gateways for unexpected process execution, outbound connections to unusual destinations, or configuration file modifications
  6. Conduct post-patch security review of VPN gateway logs for indicators of prior exploitation attempts or suspicious authentication patterns

Source

Code Red Cyber / VTA – coderedcyber.ai