Cyber Security News

Critical Check Point VPN Flaws Let Unauthenticated Attackers Execute Remote Code

Check Point has announced two critical vulnerabilities in its VPN technology that could allow unauthenticated remote attackers to execute arbitrary code on affected security gateways under certain conditions.

These vulnerabilities, tracked as CVE-2026-85102 and CVE-2026-85103, impact both Remote Access VPN and Site-to-Site VPN functionalities. Check Point said its internal research team discovered and resolved these issues and has no evidence they have been exploited in the wild.

Check Point VPN Flaws

The first vulnerability, CVE-2026-85102, involves an authentication-bypass flaw that could lead to remote code execution (RCE). According to Check Point’s advisory, this flaw could let an attacker circumvent authentication controls in vulnerable VPN deployments and execute code remotely.

Because VPN gateways are usually exposed to the internet and sit at the edge of enterprise networks, successful exploitation could give attackers a foothold in a targeted environment without valid credentials.

The second issue, CVE-2026-85103, is a heap overflow vulnerability related to ASN.1 decoding, which can also result in remote code execution.

ASN.1 is often used to encode and exchange structured data in cryptographic and networking protocols. Improper handling of maliciously crafted ASN.1 data can corrupt memory on the affected device, potentially allowing an attacker to take control of the VPN process or appliance.

Check Point classified both vulnerabilities as critical and urged customers to install the latest available Jumbo Hotfix for their deployed software versions as soon as possible.

The company did not publish technical proof-of-concept details to mitigate the risk of opportunistic exploitation before organizations can apply the necessary patches.

Customers using Check Point Live Patch will receive automatic protection, with the rollout beginning on September 9, 2026. Organizations not using Live Patch should review Check Point’s remediation guidance and manually deploy the relevant Jumbo Hotfix.

Security teams should prioritize protecting externally accessible Check Point gateways, especially those providing connectivity for remote workforces or site-to-site tunnels.

Threat actors frequently target internet-facing VPN devices because compromising them can provide a pathway into internal networks, enable credential theft, facilitate lateral movement, or support ransomware operations.

Administrators are advised to identify affected gateways, confirm the installed software release and hotfix level, and apply the vendor-provided fixes during an expedited maintenance window.

Additionally, teams should review gateway logs for any unusual VPN requests, authentication anomalies, unexpected administrative activity, configuration changes, or suspicious processes.

While Check Point has indicated that it has not observed active exploitation, the combination of unauthenticated access and remote code execution makes these vulnerabilities particularly serious.

Organizations should treat CVE-2026-85102 and CVE-2026-85103 as urgent patching priorities and ensure their perimeter VPN infrastructure is fully up to date.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection. 

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

3 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago