TechNewsReel
Live

Check Point Patches Critical VPN Flaw Enabling Remote Code Execution

A heap overflow in ASN.1 certificate decoding allows unauthenticated attackers to execute arbitrary code on security gateways.

TechNewsReel Newsroom · September 10, 2026

Check Point has released critical patches for a vulnerability in its firewall and management products that allows unauthenticated remote attackers to execute arbitrary code. The flaw, identified as CVE-2026-85103, targets the system's handling of VPN certificates during the initial handshake process.

According to Check Point Support, the vulnerability is a heap overflow located within the ASN.1 decoding flow. The flaw carries a CVSS score of 9.8, reflecting its severity and the ease with which a remote actor could exploit it. The vulnerability allows an attacker to remotely execute arbitrary code on both Management Servers and Security Gateways without requiring prior authentication.

Technical Context

The vulnerability is rooted in the processing of certificate data during VPN handshakes. Specifically, the flaw exists in the ASN.1 (Abstract Syntax Notation One) decoding process, a standard used to define data structures in networking and security certificates. When the system improperly decodes this data, it triggers a heap overflow, creating an opening for code injection.

Impacted software versions include R81.20, R82, and R82.10. Check Point also noted that several End-of-Support (EoS) versions, ranging from R80 through R81.10, are affected. This broad range of impacted versions means a significant number of legacy and current installations are potentially at risk.

Industry Implications

Because these flaws target perimeter security devices, the risk to organizational infrastructure is substantial. Firewalls and management servers serve as the primary line of defense between the public internet and private internal networks. A successful exploit of CVE-2026-85103 could allow an attacker to bypass security controls entirely or establish a persistent foothold within the internal network.

In the context of modern cybersecurity, vulnerabilities in VPN gateways are high-value targets for state-sponsored actors and ransomware groups. The ability to achieve remote code execution (RCE) on a security gateway effectively turns a defensive tool into an entry point for deeper network penetration.

Next Steps for Administrators

Check Point has disclosed the vulnerability and provided patches to mitigate the risk. Network administrators are urged to update their Security Gateways and Management Servers to the latest supported versions immediately. For those running End-of-Support versions, migrating to a supported release is the only definitive way to resolve the vulnerability. Organizations should prioritize the patching of internet-facing gateways to close the window of opportunity for remote attackers.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.