Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
_Val_
Admin
Admin

[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Hey CheckMates

Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.

To ensure continued protection, we strongly recommend installing the latest Jumbo Hotfix for your deployed version as soon as it becomes available.

Please note that customers using Check Point Live Patch will be automatically protected as the rollout begins on September 9, 2026. If you are not using Check Point Live Patch, read sk185114 for more details on how you can benefit and stay protected.

For detailed information, affected products, mitigation guidance, and remediation instructions, please refer to the following Security Advisories:
  • CVE-2026-85102: Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN - sk1000117
  • CVE-2026-85103: ASN.1 Decoding Heap Overflow Leading to Remote Code Execution - sk1000118
31 Replies
Pavol-T
Newcomer

Regarding CVE-2026-85103, to me it's not clear if gateways with VPN software blade disabled are affected too. Any ideas or further information? Thank you

0 Kudos
_Val_
Admin
Admin

This specific issue is about certificate processing, so it theoretically can be triggered in an environment even without VPN, but with VPN certificates.

This is what the CVE description saysA heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

0 Kudos
J_admin12
Contributor

Thanks,

At what time will the Spark SK articles be updated to show the new builds? Currently neither are showing the latest patched versions.

Thanks,
Jake

0 Kudos
StackCap43382
Collaborator
Collaborator

When is the CPLP package going to be pushed?

All the devices I've checked still have V18.

Will this package require any manual intervention for CPLP to apply the code fix to the processes?

 

CCSME, CCTE, CCME, CCVS
0 Kudos
(1)
StackCap43382
Collaborator
Collaborator

Also why is the Jumbo for these CVEs integrated with dozens of other fixes? This should be a targeted JHF so people can install without a repeat of the recent DHCP bug. 

CCSME, CCTE, CCME, CCVS
0 Kudos
CaseyB
Advisor

You can manually apply the CPLP to stay on your current JHF or wait for Check Point to push it to your gateways IF you have it enabled.

0 Kudos
_Val_
Admin
Admin

Answering both questions:

1. The fixes are available immediately with LivePatch packages and can be downloaded from the SKs mentioned above or automatically through the LivePatch mechanism.
2. They are also included with JHF packages in the SKs. 

You can use either way to patch.

0 Kudos
PhoneBoy
Admin
Admin

I assume this is done on a rollout basis and not done to everyone all at ones.
If you need to apply immediately, you can download the relevant update (Take 24) from: https://support.checkpoint.com/results/sk/sk185114 

0 Kudos
StackCap43382
Collaborator
Collaborator

Done that in a lab.

Waiting to see if it actually armes the ready processes or not.

 

 

[Expert@FWA-01:0]# cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
vpn1:iked ready livepatch 0/0 2026-07-15 08:13:55 sk185033
vpn1:vpnd ready livepatch 0/0 2026-07-15 08:13:55 sk185033

One row per <name>:<proc> deployment (revert/status target). Use `cplp status --patch-id <name>` for live per-pid state.
[Expert@FWA-01:0]# autoupdatercli install /home/admin/urgent_security_updates_R81_20_Bundle_T24_AutoUpdate.tar

Install request of component urgent_security_updates version 24 handled. To see installation status, see logs: /opt/CPInstLog/AutoUpdater.log and /opt/CPInstLog/AutoUpdateLogs/urgent_security_updates

[Expert@FWA-01:0]# cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpcert:cpca* ready livepatch 0/0 2026-09-09 15:01:30 CVE-2026-85102 CVE-2026-85103
cpcert:ike* armed livepatch 1/1 2026-09-09 15:01:30 CVE-2026-85102 CVE-2026-85103
cpcert:vpn* armed livepatch 1/1 2026-09-09 15:01:30 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-09 15:01:30 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* armed livepatch 2/2 2026-09-09 15:01:30 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-09 15:01:29 CVE-2026-85102 CVE-2026-85103
vpn1:iked* jumbofix livepatch 0/0 2026-07-15 09:13:55 sk185033
vpn1:vpnd* jumbofix livepatch 0/0 2026-07-15 09:13:55 sk185033

* reports to the management audit trail (`cplp coverage disable --patch-id <name>` to stop).
[Expert@FWA-01:0]#

CCSME, CCTE, CCME, CCVS
0 Kudos
travelmaniac
Explorer

hm...
Manually rolling that out is nearly as much effort, as doing an HFA install..
(At least the way like that is described in that SK...)

At least an "update now"  flag in the cplp would be great.

0 Kudos
henfii
Participant

Hello, where can I find the exact firmware for Spark? There are still unupdated FWs build on the site. 

Thank you

ccsjnw
Collaborator

None of the download links work:

https://support.checkpoint.com/results/sk/sk1000117/
https://support.checkpoint.com/results/sk/sk1000118/
Broken Links.png
https://support.checkpoint.com/results/download/145356

Also, if I click Check for Updates in the Gaia WebUI, it shows Jumbo Take 122 for R82 as being the latest available and Jumbo Take 40 as the latest available for R82.10.

I received the email notification from CheckPoint 48 minutes ago.

0 Kudos
_Val_
Admin
Admin

I double-checked; the download links are working.

0 Kudos
CaseyB
Advisor

The Live Patch download links work here. 

I have already applied Urgent Take 24 and it works well. Better than the jumbo approach for sure. 

ccsjnw
Collaborator

CaseyB, that page is blank when I open (and fresh it) from the UK...

0 Kudos
CaseyB
Advisor

0 Kudos
ccsjnw
Collaborator

Still not working here:

Broken Links3.png
See the above screenshot...
Are you positive that these links have been made available to customers, and not just internally?

0 Kudos
CaseyB
Advisor

That's what I used as a customer. ¯\_(ツ)_/¯

0 Kudos
ccsjnw
Collaborator


The WebUI in Gaia is now showing the full update packages for both R82 and R82.10, so I'm using that method...

0 Kudos
Magnus-Holmberg
MVP Silver
MVP Silver

Question.

We see that we have.

[CPUpdates]
BUNDLE_URGENT_SECURITY_UPDATE_R81_20_AUTOUPDATE Take: 18

But none of our boxes we are able to run

[Expert@se-sec-fw001_n1:0]# cplp list
bash: cplp: command not found

Regards,
Magnus

https://www.youtube.com/c/MagnusHolmberg-NetSec
0 Kudos
Fr4nkys
Participant

hello magnus you can find it inside here:

Just run the command like this copy and paste : /usr/local/bin/cplp list

  

0 Kudos
Magnus-Holmberg
MVP Silver
MVP Silver

Ye that works 🙂

[Expert@se-sec-vsx030_n1:0]# /usr/local/bin/cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
vpn1:iked ready livepatch 0/0 2026-09-02 11:57:45
vpn1:vpnd ready livepatch 0/0 2026-09-02 11:57:45

https://www.youtube.com/c/MagnusHolmberg-NetSec
0 Kudos
(1)
Fernando
Explorer

And Mobile Access ??

0 Kudos
Alex-
MVP Silver
MVP Silver

Since the vulnerability was found internally, are there any indicators in logs which would allow to identify attempts?

_Val_
Admin
Admin

We did not see any evidence of those vulnerabilities being exploited externally. IOCs are only relevant for existing exploits. 

0 Kudos
Cypress
Contributor

We discovered the existence of CPLP this morning with these announcements.  We are a little confused on the functionality of this feature.  When we ran the commands 'cplp list" on our gateways this morning it showed only the older iked and vpnd fixes in the list, and showed "ready" status for both of them.  However when we ran the command again about 30 minutes later, it now shows several additional entries including the ones released today, and showing some as "armed" status, some as 'ready" status, and some as "jumbofix" status.

It is almost like CPLP was not actually fully functional until we entered the "cplp list" command?

0 Kudos
CaseyB
Advisor

It is possible you might have received the auto-update within that time frame. You can check the log on your gateway to verify.

  • /opt/CPInstLog/AutoUpdater.log
  • Look for "urgent_security_updates_R82_Bundle_T"

T24 would be the new one.

Timestamps from our gateway.

urgent-t17.pngurgent-t24.png

0 Kudos
PetterD
Collaborator

I can see that the patch is downloaded and implementet for all processes except cpca and vpnrad.
Do we need to reboot the whole VSX-box to make it arm these processes aswell or will it happen automagically ?


[Expert@fw-vsxcluster-node1:0]# cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpcert:cpca* ready livepatch 0/0 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:ike* armed livepatch 5/5 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:vpn* armed livepatch 7/7 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* armed livepatch 6/6 2026-09-09 15:25:35 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-09 15:25:33 CVE-2026-85102 CVE-2026-85103
vpn1:ike* armed livepatch 5/5 2026-07-09 09:25:04 sk185033
vpn1:vpn* armed livepatch 7/7 2026-07-09 09:25:04 sk185033

CCSM / CCSE / CCVS / CCTE
0 Kudos
Machine_Head
Advisor
Advisor

I believe "ready" state is because the process is actually not running on the box

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events