Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
_Val_
Admin
Admin
Jump to solution

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Hey CheckMates

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

To ensure continued protection, we strongly recommend installing the latest Jumbo Hotfix for your deployed version as soon as it becomes available.

Please note that customers using Check Point Live Patch will be automatically protected as the rollout begins on September 9, 2026. If you are not using Check Point Live Patch, read sk185114 for more details on how you can benefit and stay protected.

For detailed information, affected products, mitigation guidance, and remediation instructions, please refer to the following Security Advisories:
  • CVE-2026-85102: Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN - sk1000117
  • CVE-2026-85103: ASN.1 Decoding Heap Overflow Leading to Remote Code Execution - sk1000118
85 Replies
travelmaniac
Participant

@_Val_: Yes, i am fine with having to login to download the fixes.

But i would expect to have a link in the SK, which then forces me to login.
Not just a page without any working link.

E.g: sk185114 - Check Point Live Patch (CPLP) has a download link, even if you are not logged in.
(you then are forced to do a login, to retreive the download.)

CaseyB
Advisor

The Live Patch download links work here. 

I have already applied Urgent Take 24 and it works well. Better than the jumbo approach for sure. 

ccsjnw
Collaborator

CaseyB, that page is blank when I open (and fresh it) from the UK...

0 Kudos
CaseyB
Advisor
0 Kudos
ccsjnw
Collaborator

Still not working here:

Broken Links3.png
See the above screenshot...
Are you positive that these links have been made available to customers, and not just internally?

0 Kudos
CaseyB
Advisor

That's what I used as a customer. ¯\_(ツ)_/¯

0 Kudos
ccsjnw
Collaborator


The WebUI in Gaia is now showing the full update packages for both R82 and R82.10, so I'm using that method...

0 Kudos
Magnus-Holmberg
MVP Silver
MVP Silver

Question.

We see that we have.

[CPUpdates]
BUNDLE_URGENT_SECURITY_UPDATE_R81_20_AUTOUPDATE Take: 18

But none of our boxes we are able to run

[Expert@se-sec-fw001_n1:0]# cplp list
bash: cplp: command not found

Regards,
Magnus

https://www.youtube.com/c/MagnusHolmberg-NetSec
Fr4nkys
Participant

hello magnus you can find it inside here:

Just run the command like this copy and paste : /usr/local/bin/cplp list

  

Magnus-Holmberg
MVP Silver
MVP Silver

Ye that works 🙂

[Expert@se-sec-vsx030_n1:0]# /usr/local/bin/cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
vpn1:iked ready livepatch 0/0 2026-09-02 11:57:45
vpn1:vpnd ready livepatch 0/0 2026-09-02 11:57:45

https://www.youtube.com/c/MagnusHolmberg-NetSec
0 Kudos
(1)
rfu
Explorer

I have an offline Management Server with R81.20 / T161 and there is no cplp`bash: /usr/local/bin/cplp: No such file or directory`
I do have /opt/AutoUpdater/latest/bin/autoupdatercli though. Can it be applied via autoupdatercli?

0 Kudos
Duane_Toler
MVP Silver
MVP Silver

You can, but you must use the manual packages to update.  You may need to update the AutoUpdater package and its components first.  This is described in the SK article and with the links to other AutoUpdater articles (also listed within the article for this advisory).

 

--
Ansible for Check Point APIs series: https://www.youtube.com/@EdgeCaseScenario and Substack
Fernando
Explorer

And Mobile Access ??

0 Kudos
Alex-
MVP Silver
MVP Silver

Since the vulnerability was found internally, are there any indicators in logs which would allow to identify attempts?

_Val_
Admin
Admin

We did not see any evidence of those vulnerabilities being exploited externally. IOCs are only relevant for existing exploits. 

0 Kudos
Guard
Explorer

I can see that the patch is downloaded and implementet for all processes except cpca and vpnrad.
Do we need to reboot the whole VSX-box to make it arm these processes aswell or will it happen automagically ?

 

Output:

[Expert@fw-vsxcluster-node1:0]# cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpcert:cpca* ready livepatch 0/0 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:ike* armed livepatch 5/5 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:vpn* armed livepatch 7/7 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* armed livepatch 6/6 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-09 15:25:33 CVE-2026-85102 CVE-2026-85103
vpn1:ike* armed livepatch 5/5 2026-07-09 09:25:04 sk185033
vpn1:vpn* armed livepatch 7/7 2026-07-09 09:25:04 sk185033

 

 

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

Ready means the live patch is present, but no relevant processes are running. Armed is the same state, but relevant processes have been found and patched in RAM.

Cypress
Contributor

We discovered the existence of CPLP this morning with these announcements.  We are a little confused on the functionality of this feature.  When we ran the commands 'cplp list" on our gateways this morning it showed only the older iked and vpnd fixes in the list, and showed "ready" status for both of them.  However when we ran the command again about 30 minutes later, it now shows several additional entries including the ones released today, and showing some as "armed" status, some as 'ready" status, and some as "jumbofix" status.

It is almost like CPLP was not actually fully functional until we entered the "cplp list" command?

0 Kudos
CaseyB
Advisor

It is possible you might have received the auto-update within that time frame. You can check the log on your gateway to verify.

  • /opt/CPInstLog/AutoUpdater.log
  • Look for "urgent_security_updates_R82_Bundle_T"

T24 would be the new one.

Timestamps from our gateway.

urgent-t17.pngurgent-t24.png

RemoteUser
Advisor

more /opt/CPInstLog/AutoUpdater.log | grep urgent_security_updates_R81.20
*N* %2026-07-13 12:33:11% : Importing package urgent_security_updates_R81_20_Bundle_T10_AutoUpdate.tar for component urgent_security_updates version 10 branch urgent_security_update_R81_20_AutoUpdate
*N* %2026-07-13 12:33:17% : <action = install, component = urgent_security_updates, build = 10, package_name = urgent_security_updates_R81_20_Bundle_T10_FULL.tgz, source = INTERNAL>
*N* %2026-09-01 09:01:15% : Importing package urgent_security_updates_R81_20_Bundle_T18_AutoUpdate.tar for component urgent_security_updates version 18 branch urgent_security_update_R81_20_AutoUpdate
*N* %2026-09-01 09:01:20% : <action = install, component = urgent_security_updates, build = 18, package_name = urgent_security_updates_R81_20_Bundle_T18_FULL.tgz, source = INTERNAL>

unable to understand why take 24 not pushed....

PetterD
Collaborator

I can see that the patch is downloaded and implementet for all processes except cpca and vpnrad.
Do we need to reboot the whole VSX-box to make it arm these processes aswell or will it happen automagically ?


[Expert@fw-vsxcluster-node1:0]# cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpcert:cpca* ready livepatch 0/0 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:ike* armed livepatch 5/5 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:vpn* armed livepatch 7/7 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* armed livepatch 6/6 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-09 15:25:33 CVE-2026-85102 CVE-2026-85103
vpn1:ike* armed livepatch 5/5 2026-07-09 09:25:04 sk185033
vpn1:vpn* armed livepatch 7/7 2026-07-09 09:25:04 sk185033

CCSM / CCSE / CCVS / CCTE
0 Kudos
Machine_Head
Advisor
Advisor

I believe "ready" state is because the process is actually not running on the box

0 Kudos
PetterD
Collaborator

Would be great if thats the case, Check Point should definately clarify some more in their sk`s :).

According to sk185114, "ready" means "The patch is installed and waiting. It will be applied automatically as soon as the target process starts."


On the box i cant find "cpca" process (and would not expect to since its a VSX gateway and not Management so you are probably correct 🙂

CCSM / CCSE / CCVS / CCTE
0 Kudos
Ruan_Kotze
MVP Gold
MVP Gold

As soon as the process executes it will switch status to armed.

For example, the cpca process is Check Point Internal CA which only runs on a management appliance.

The vpnrad process is a new one to me, also does not seem documented in sk97638.

0 Kudos
Machine_Head
Advisor
Advisor

few Commands for autoudpatercli

autoupdatercli show urgent_security_updates

autoupdatercli update_component urgent_security_updates

 

Note:
autoupdatercli update_component command only downloads the package if the new one is "rolled out" to your device.
You just get ahead of the scheduled job

David_Evans
Advisor

What controls "rolled out to your device?"      I've manually installed the critical ones, but nothing has automatically advanced beyond version 17.

0 Kudos
Machine_Head
Advisor
Advisor

CheckPoint does a progressive rollout i guess, i've checked this morning and all the firewalls i manage are now patched, for some it was overnight (europe)

0 Kudos
David_Evans
Advisor

Yes, something triggered and over the ~3 hour check in timer, most everything updated / patched.     That will need to be a discussion if there is a active attack.   Where does 'my' account specifically fall in the staged roll out and is there a button to "go now". 

I know.. it didn't exist yesterday and I want it to be faster today...    But that is the roll of a customer right?

0 Kudos
_Val_
Admin
Admin

As mentioned in the original statement, we do not have any indication that either vulnerability was actively exploited. Both CVEs were discovered internally.

0 Kudos
Henrik_Noerr1
Advisor

CPLP has a lot of potential, the need for patch will only increase - But I think this thread clearly highlights that cplp is early days.

The documentation is almost zero.

- cplp only works with full path

- why are new cplp versions needed for new live patches? When are these pushed?

- when does a proc go from ready to armed?

- how do I set 'frozen' periods on when arming is allowed? We have frozen periods for autoupdater (although very limited)

- do we have an audit log browsable in smartlog?

(1)

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events