Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
_Val_
Admin
Admin
Jump to solution

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Hey CheckMates

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

To ensure continued protection, we strongly recommend installing the latest Jumbo Hotfix for your deployed version as soon as it becomes available.

Please note that customers using Check Point Live Patch will be automatically protected as the rollout begins on September 9, 2026. If you are not using Check Point Live Patch, read sk185114 for more details on how you can benefit and stay protected.

For detailed information, affected products, mitigation guidance, and remediation instructions, please refer to the following Security Advisories:
  • CVE-2026-85102: Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN - sk1000117
  • CVE-2026-85103: ASN.1 Decoding Heap Overflow Leading to Remote Code Execution - sk1000118
87 Replies
Machine_Head
Advisor
Advisor

- when does a proc go from ready to armed?
Ready means the process is not running, otherwise it'd go "armed". That's my take

- how do I set 'frozen' periods on when arming is allowed? We have frozen periods for autoupdater (although very limited)
CPLP works via autoupdatercli so if you have a frozen period there the same applies to CPLP (it wouldnt download an update)

- do we have an audit log browsable in smartlog?
Search "live patch" in audit logs

0 Kudos
Henrik_Noerr1
Advisor

Hey,

I have clusters that definitely have the procs running. I am yet to see armed go to ready - anywhere.

I see that CPLP documentation is evolving as we speak. Maybe to go to armed mode would need a reboot, it looks like it. 

On the arming frozen periods, I am not so sure. 

 

live patch - gives zero hits in audit logs in an MDM managing 40 clusters.

0 Kudos
Zolocofxp
Collaborator

We are still using R81,10 and will not update for the next 4-5 weeks. How can I apply the suggested mitigation without affecting my remote users?

0 Kudos
cjrnz
Contributor

same, I have a pair on R81.10 that are scheduled for replacement later this month.  "disable implied rules for VPN" is far too vague, I'd like to know precisely what lines to comment out of implied_rules.def to achieve that.  no JHF available, no CPLP.  Mitigation is the only option for these (or anything older).

0 Kudos
genisis__
MVP Silver
MVP Silver

Val - please note the Quantum spark links need correcting, the image file for 2000 appliances is on the 2560 - 2590 link and the 2560 - 2590 image is on the 2000 link.

 

0 Kudos
Aaron-pr
Participant

The 15x5/1575RIMG link is still the previous build as well. 

0 Kudos
K_R_V
Collaborator

I did a refresh of this page and the build was now correct.

0 Kudos
Duane_Toler
MVP Silver
MVP Silver

One question I haven't seen answered:  Do the live patch updates require any specific jumbo HFA to be installed first?

For example, I have an R82 host with JHF 107 that has the live patch installed and "armed".  I have some other hosts with JHF 103 that haven't gotten the update yet.  I have an R81.20 host with JHF 127 which does have the live patch armed. Many other R82 hosts with JHF 107 that don't yet have the live patch, nor do they have the latest "urgent_security_updates" components; I tried to update this component manually but nothing changed and no error was reported.

Seems like we don't have any way to influence these updates without manually installing packages, and that can be annoying to push out no matter how much Ansible tooling I have. 🙂  I haven't finished my draft version of the autoupdater Ansible modules yet.  I started on it but got moved to another project.  (maybe it's time... ?)

Thanks!

 

--
Ansible for Check Point APIs series: https://www.youtube.com/@EdgeCaseScenario and Substack
0 Kudos
MeravAlon
Employee
Employee

No. it can be installed on any Jumbo HF in versions R81.20, R82.00, R82.10 

Duane_Toler
MVP Silver
MVP Silver

Yep, I see that now!  Thanks!

My best guess is that Check Point was slow-walking these updates all day then around 2100 UTC they opened the gates to all.  All of my customer gateways and management servers simultaneously started getting the updates around that time and over the next 1.5 hours.

Same thing @Machine_Head noted.

 

--
Ansible for Check Point APIs series: https://www.youtube.com/@EdgeCaseScenario and Substack
0 Kudos
JoSec
Collaborator

I am very ecstatic Check Point can close the gap so quickly with CPLP and thank you to all of those that worked on this feature. This is a big win! I think there is a marketing opportunity with some T-shirts that say, "I sure do love me... some CPLP!" Seriously though, it is a great feature.

Alex-
MVP Silver
MVP Silver

The advisory has been updated to also patch the SMS as a matter of urgency, regarding CVE-2026-85103.

ccsjnw
Collaborator


Just received an update this morning, that says the patch must be installed on *all* management servers:

Update.png

0 Kudos
_Val_
Admin
Admin

Correct, I mentioned it above, the second CVE is about certificate handling, and considering all MGMT servers have CPCA, they have to be patched.

0 Kudos
mujma
Explorer

Hello

If I have disabled blade VPN and I/m installed the patch on the management station, can I postpone patching the gateways for a few days?

 

0 Kudos
_Val_
Admin
Admin

This is not recommended. Also, LivePatch does not require a reboot and does not cause any downtime or cluster failover.

0 Kudos
mujma
Explorer

It looks like we have a path via CPLP on both gateways:

# cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpcert:cpca* ready livepatch 0/0 2026-09-10 00:03:49 CVE-2026-85102 CVE-2026-85103
cpcert:ike* armed livepatch 14/14 2026-09-10 00:03:49 CVE-2026-85102 CVE-2026-85103
cpcert:vpn* armed livepatch 1/1 2026-09-10 00:03:49 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-10 00:03:49 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* armed livepatch 27/27 2026-09-10 00:03:49 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-10 00:03:47 CVE-2026-85102 CVE-2026-85103
vpn1:iked* jumbofix livepatch 0/0 2026-07-09 09:20:01 sk185033
vpn1:vpnd* jumbofix livepatch 0/0 2026-07-09 09:20:01 sk185033

0 Kudos
ccsjnw
Collaborator

I have already patched my customer's Security Gateways that have IPSEC VPN and/or Mobile Access Blades enabled, and I have also patched the Management Server.

The customer also has several other Security Gateways that do not have IPSEC VPN or Mobile Access Blades enabled. Is it OK to leave these on R82 Jumbo HFA Take 122 for now?

0 Kudos
_Val_
Admin
Admin

As I mentioned, we recommend applying LivePatch to the whole estate, regardless of VPN is being used.

0 Kudos
Oliver_Fink
Advisor
Advisor

@_Val_, could you be a little more precise, please? 

sk1000118 mentions "Affected Products: Security Management Server, Security Gateway, Check Point Spark Firewall" – not restricted to anything with VPN. And we see "wstlsd" and "cprid" live-patched – nothing to do with VPN. Are all security gateways affected?

No one at Check Point can or wants to tell me definitely. But that answer is crucial!

0 Kudos
Alex-
MVP Silver
MVP Silver

CPLP actions appear in the Audit Logs. Cool.

0 Kudos
Dattatray
Explorer

The gateways have been successfully auto-updated with the Live Patch; however, the Management Server has not been updated.

Could you please advise how we should proceed with applying the Live Patch on the Management Server?

Version R81.20 JHF TAKE 127

0 Kudos
ccsjnw
Collaborator


Do CheckPoint have any CPLP premier material available or videos to watch?
I literally did not know of its existence until yesterday and now I'm playing catch-up...

I'm looking at the autoupdatecli command and there are a lot of options. 

If I want to be 100% certain that a Security Gateway will only download and install an urgently required Live Patch automatically (but never automatically install a full Jumbo HotFix Package or Reboot automatically), is there a simple command to show this clearly?

It looks like the correct command to enable this functionality is:
autoupdatercli enable urgent_security_updates

But is says security updates, not Live Patches, so I'm concerned that may not be correct.

I'm not finding the SK articles particularly informative or helpful...

0 Kudos
Magnus-Holmberg
MVP Silver
MVP Silver

Good video in regards to it.
https://youtu.be/6cNrNRAjvEw?si=JICZpcchV1Bz9i6D


 

 

https://www.youtube.com/c/MagnusHolmberg-NetSec
(1)
ccsjnw
Collaborator

Thanks for the link Magnus,

It's an extremely informative presentation by Aviv Abramovich. I would urge everybody to watch this and to give it your full attention... there are big changes coming:

https://youtu.be/6cNrNRAjvEw?si=JICZpcchV1Bz9i6D

0 Kudos
ccsjnw
Collaborator

I'm still unclear with regard to the proper enablement of Live Patching...

cplp list

cplp list.png

Why is the same CVE shown more than once and how can it have the status of both Ready and Armed?

autoupdatercli show urgent_security_updates

I see:
Urgent Security Updates.png

What do I actually need to do to make the live patches take effect?

Do I just need to issue the command:

autoupdatercli update_component urgent_security_updates

And do I only need to issue this command just once for the whole LivePatching process to automatically up-to-date ???

I been through various SK articles and it's still not clear to me... 


Please can the terminology be improved:
Wording.png

The word ARMED in this context is very ambiguous. ENFORCED would be far clearer, and not open to the wrong interpretation of the word.

According to the above, Ready means Installed and Waiting
Waiting for what target process? Can something be installed, but not active? Perhaps use the wording, Deployed, but not yet active or Deployed, but not yet enforced - it needs to be crystal clear.


I think we all just need some further clarity, as we're all playing catch up, and don't want to break anything...

LivePatch is clearly an impressive technology - thanks for the continued innovations.

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

Based on your 'cplp list', the live patch is already present and working on that system.

For ready versus armed, consider a firewall where you have the IPSec VPN feature unchecked. That would mean right now it wouldn't run iked, vpnd, and so forth, so there are no processes to patch. If you then check the IPSec VPN feature, use the firewall in a VPN community, and push policy, it would start various VPN-related processes. CPLP is watching for those processes to start, and it will attempt to patch them if it sees them.

Ready means it's ready to patch the processes if you enable the feature. Armed means it has detected relevant processes and patched them in RAM.

Agreed that the wording could be better. The state currently described as 'ready' seems more reasonably 'armed' to me: the system is prepared to take action, but hasn't taken any action yet. Like an alarm which is armed, but not firing. That said, the current wording is at least used consistently, which matters more than picking exactly the right words.

0 Kudos
Alex-
MVP Silver
MVP Silver

Uploaded two Spark Pro, 1800 and 1900 clusters today from R82.10.10 2242 to 2325, centrally managed by Smart-1 Cloud.

No issues with both 1900. Doing one of the 1800, it worked but after rebooting, policy install fails and it reports management unreachable. Clustering works. After rebooting it, it reverted to 2242. Will try again later.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events