Check Point has addressed two critical vulnerabilities in its firewall and management products related to VPN certificate handling. These flaws, identified as CVE-2026-85102 and CVE-2026-85103, could potentially allow unauthenticated remote attackers to execute code under unspecified conditions. The first vulnerability involves improper validation of certificate trust during VPN negotiation, affecting Check Point's Security Gateways. The second involves a heap-based buffer overflow during the decoding of a VPN certificate's ASN.1 structure, impacting both Quantum Security Management and Quantum Security Gateway systems. Both vulnerabilities carry a high CVSS score of 9.8, indicating their severity.

Check Point disclosed these vulnerabilities on September 9 and began deploying fixes immediately. The company discovered these flaws internally and has not found evidence of their exploitation in the wild. Customers have two options for addressing these vulnerabilities: Check Point Live Patch, which automatically protects systems as updates are rolled out, and the installation of the latest Jumbo Hotfix for their respective software versions.

Although Check Point has provided advisories sk1000117 and sk1000118 for detailed guidance, some customers have reported issues with accessing the updates and challenges in applying the mitigations. Additionally, there has been confusion over which specific product versions are affected and how to implement the recommended mitigations without disrupting existing setups. Despite these challenges, Check Point assures that the vulnerabilities have not been exploited externally, and the company is actively assisting customers with the update process.