hacker-news · Crawled Sep 10, 2026

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

Read original article ↗

AI Summary

Check Point disclosed two critical vulnerabilities in its Security Gateways and Security Management Server products that could allow unauthenticated remote code execution during VPN certificate processing. The first, CVE-2026-85102, stems from improper certificate trust validation, while the second, CVE-2026-85103, is a heap-based buffer overflow in ASN.1 certificate decoding. Both vulnerabilities carry a CVSS score of 9.8 and affect multiple versions of Check Point's R81 and R82 product lines. While Check Point states the flaws were internally discovered and not yet exploited, mitigation is advised through Live Patch or Jumbo Hotfix updates, though some customers reported delays in patch availability and unclear mitigation instructions.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.