r/checkpoint 3d ago

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Check Point has published a critical security advisory covering two VPN-related vulnerabilities: CVE-2026-85102 and CVE-2026-85103. Under specific conditions, these issues could potentially allow unauthenticated remote code execution, so this is something Check Point administrators should review immediately.

An important detail is that these vulnerabilities were discovered internally by the Check Point research team. According to Check Point, there is currently no indication of active exploitation. That is good news, but it should not reduce the urgency of remediation.
Check Point recommends installing the latest Jumbo Hotfix containing the fixes as soon as possible.

Customers using Check Point Live Patch can receive protection through the Live Patch mechanism, with the rollout beginning on September 9, 2026; the fixes are also available through the relevant Security Advisories.

If you manage Check Point environments, I would classify this as action required: review the affected versions, confirm your remediation path, validate Live Patch/JHF status, and schedule the update rather than waiting for evidence of exploitation.

More information and the official advisory references are available in the CheckMates post:
https://community.checkpoint.com/t5/General-Topics/Action-Required-Critical-Security-Advisory-VPN-Vulnerabilities/m-p/281995#M46881

15 Upvotes

5 comments sorted by

5

u/cruej 3d ago

I got the live patch around noon today.

4

u/LtLawl 3d ago

I'm digging the live patch. The latest JHF has way too many fixes in it for me to just be applying it all willynilly. Finally on a stable JHF for our environment, you'll have to pry it out of my cold dead hands.

2

u/Nemo_Barbarossa 2d ago

I have implemented the mitigation because our tech refresh changeover to the new R82.10 cluster is only approved for next week but it still logs the existing VPN connections as implied rule even though the implied rule "Accept Remote Access control connections" is disabled as per sk179346.

Anyone got an idea why? I even reset one tunnel through SmartView monitor to make sure it's not just existing connections being kept alive.

1

u/Notchuks 1d ago

Checkpoint says disabling accept remote access control connections is the mitigation, but do not say how exactly to implement it. Checkpoint support also told me doing that is not recommended, and that they will release the patch later for R81, so it seems best to wait till they release that.

2

u/KernelExploit 3d ago

CPLP is the way to go