Check Point Releases Patches for Two Critical VPN Flaws Allowing Unauthenticated Remote Code Execution
Check Point Software announced that it has released security updates for two newly disclosed VPN vulnerabilities, identified as CVE-2026-85102 and CVE-2026-85103, each assigned a maximum CVSS score of 9.8. The flaws can be triggered without authentication and may permit remote code execution under certain conditions, prompting the vendor to label them as critical.
The two vulnerabilities affect Check Point's Remote Access VPN implementation. According to the advisory, the weaknesses stem from improper handling of network packets that can be crafted to bypass normal security checks, ultimately allowing an attacker to inject and run arbitrary code on the target system. Both CVEs share a similar attack vector, though they exploit distinct code paths within the VPN service.
Virtual private networks are widely used to secure remote connections for enterprises, especially as hybrid work models persist. A remote code execution (RCE) vulnerability in such a gateway can give threat actors the ability to compromise network perimeters, exfiltrate data, or deploy additional malware. The severity rating of 9.8 places the issues just below the highest possible score, reflecting the potential impact and the lack of required credentials.
Check Point urged customers to apply the provided patches immediately. The company’s security team has made the updates available through its standard firmware distribution channels and recommends verifying that all VPN appliances are running the latest version. Organizations that have not yet updated are advised to review network logs for any signs of anomalous traffic that could indicate exploitation attempts.
The disclosure underscores the ongoing challenge of maintaining secure remote‑access infrastructure. Industry analysts note that VPN vulnerabilities have surfaced repeatedly in recent years, reinforcing the need for continuous monitoring and rapid patch deployment. As the patches roll out, security teams will likely assess the scope of affected deployments and may conduct additional hardening measures to mitigate future risks.
Comments (0)
Be the first to comment.
Join the discussion