AI Weekly Malaysia

Back to items Summaries

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

ID
23162
Status
summarized
Published
10 Sep 2026, 7:45 PM
Fetched
10 Sep 2026, 9:12 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.0
Created
10 Sep 2026, 9:15 PM
Tags
Audience
developers

What happened

Check Point disclosed two 9.8 CVSS vulnerabilities (CVE-2026-85102 and CVE-2026-85103) in its Quantum Security Gateway and Security Management Server products, both enabling unauthenticated remote code execution via VPN certificate handling flaws. Fixes began shipping September 9, 2026; affected versions include R82.10 JHF Take 43 or below, R82 JHF Take 125 or below, and R81.20 JHF Take 165 or below. Check Point says it found the flaws internally and has no evidence of active exploitation.

Why it matters

Only relevant if your organization runs Check Point Quantum firewalls or Spark appliances with VPN enabled; if so, prioritize applying the Jumbo Hotfix immediately since both flaws are unauthenticated RCE reachable during VPN negotiation. For most builders in this community not managing Check Point infrastructure, no action is needed.

Discussion angle

Brief mention only: how enterprise firewall CVEs like this rarely affect typical SaaS/startup stacks, and when security news should vs. shouldn't make your weekly cut.

Top