Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
_Val_
Admin
Admin

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Hey CheckMates

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

To ensure continued protection, we strongly recommend installing the latest Jumbo Hotfix for your deployed version as soon as it becomes available.

Please note that customers using Check Point Live Patch will be automatically protected as the rollout begins on September 9, 2026. If you are not using Check Point Live Patch, read sk185114 for more details on how you can benefit and stay protected.

For detailed information, affected products, mitigation guidance, and remediation instructions, please refer to the following Security Advisories:
  • CVE-2026-85102: Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN - sk1000117
  • CVE-2026-85103: ASN.1 Decoding Heap Overflow Leading to Remote Code Execution - sk1000118
72 Replies
genisis__
MVP Silver
MVP Silver

Val - please note the Quantum spark links need correcting, the image file for 2000 appliances is on the 2560 - 2590 link and the 2560 - 2590 image is on the 2000 link.

 

0 Kudos
Aaron-pr
Participant

The 15x5/1575RIMG link is still the previous build as well. 

0 Kudos
K_R_V
Collaborator

I did a refresh of this page and the build was now correct.

0 Kudos
Duane_Toler
MVP Silver
MVP Silver

One question I haven't seen answered:  Do the live patch updates require any specific jumbo HFA to be installed first?

For example, I have an R82 host with JHF 107 that has the live patch installed and "armed".  I have some other hosts with JHF 103 that haven't gotten the update yet.  I have an R81.20 host with JHF 127 which does have the live patch armed. Many other R82 hosts with JHF 107 that don't yet have the live patch, nor do they have the latest "urgent_security_updates" components; I tried to update this component manually but nothing changed and no error was reported.

Seems like we don't have any way to influence these updates without manually installing packages, and that can be annoying to push out no matter how much Ansible tooling I have. 🙂  I haven't finished my draft version of the autoupdater Ansible modules yet.  I started on it but got moved to another project.  (maybe it's time... ?)

Thanks!

 

--
Ansible for Check Point APIs series: https://www.youtube.com/@EdgeCaseScenario and Substack
0 Kudos
MeravAlon
Employee
Employee

No. it can be installed on any Jumbo HF in versions R81.20, R82.00, R82.10 

JoSec
Collaborator

I am very ecstatic Check Point can close the gap so quickly with CPLP and thank you to all of those that worked on this feature. This is a big win! I think there is a marketing opportunity with some T-shirts that say, "I sure do love me... some CPLP!" Seriously though, it is a great feature.

Alex-
MVP Silver
MVP Silver

The advisory has been updated to also patch the SMS as a matter of urgency, regarding CVE-2026-85103.

ccsjnw
Collaborator


Just received an update this morning, that says the patch must be installed on *all* management servers:

Update.png

0 Kudos
_Val_
Admin
Admin

Correct, I mentioned it above, the second CVE is about certificate handling, and considering all MGMT servers have CPCA, they have to be patched.

0 Kudos
mujma
Explorer

Hello

If I have disabled blade VPN and I/m installed the patch on the management station, can I postpone patching the gateways for a few days?

 

0 Kudos
_Val_
Admin
Admin

This is not recommended. Also, LivePatch does not require a reboot and does not cause any downtime or cluster failover.

0 Kudos
mujma
Explorer

It looks like we have a path via CPLP on both gateways:

# cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpcert:cpca* ready livepatch 0/0 2026-09-10 00:03:49 CVE-2026-85102 CVE-2026-85103
cpcert:ike* armed livepatch 14/14 2026-09-10 00:03:49 CVE-2026-85102 CVE-2026-85103
cpcert:vpn* armed livepatch 1/1 2026-09-10 00:03:49 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-10 00:03:49 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* armed livepatch 27/27 2026-09-10 00:03:49 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-10 00:03:47 CVE-2026-85102 CVE-2026-85103
vpn1:iked* jumbofix livepatch 0/0 2026-07-09 09:20:01 sk185033
vpn1:vpnd* jumbofix livepatch 0/0 2026-07-09 09:20:01 sk185033

0 Kudos
ccsjnw
Collaborator

I have already patched my customer's Security Gateways that have IPSEC VPN and/or Mobile Access Blades enabled, and I have also patched the Management Server.

The customer also has several other Security Gateways that do not have IPSEC VPN or Mobile Access Blades enabled. Is it OK to leave these on R82 Jumbo HFA Take 122 for now?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events