Check Point VPN certificate mitigation guidance
Advisory/Mitigation
Summary
Hide ▲
Show ▼
Check Point directed affected customers to Live Patch or the latest Jumbo Hotfix for its VPN certificate flaws, with rollout beginning on September 9. The guidance matters because some deployments could not patch immediately and had to rely on mitigation steps instead.
Related Happenings
Check Point VPN certificate security patch release (CVE-2026-85102, CVE-2026-85103)
Security Patch Release
H score53
First: 10.09.2026 14:45
Last: 10.09.2026 14:45
Sources 1
How related:
Check Point disclosed the flaws on September 9 in a notice to its customer community, and began delivering fixes the same day.
About this happening:
Check Point began delivering fixes on September 9 for CVE-2026-85102 and CVE-2026-85103, two critical VPN certificate flaws in Security Gateways and Secu...
Check Point VPN certificate security patch release (CVE-2026-85102, CVE-2026-85103)
Security Patch ReleaseHow related: Check Point disclosed the flaws on September 9 in a notice to its customer community, and began delivering fixes the same day.
About this happening: Check Point began delivering fixes on September 9 for CVE-2026-85102 and CVE-2026-85103, two critical VPN certificate flaws in Security Gateways and Secu...
Check Point Security Gateways and Security Management Server VPN certificate flaws (multiple vulnerabilities)
Vulnerability
H score53
First: 10.09.2026 14:45
Last: 10.09.2026 14:45
Sources 1
How related:
The first flaw, CVE-2026-85102, is a failure to properly validate certificate trust during VPN negotiation. Its CVE record says an unauthenticated remote attacker may be able to run code on the Security Gateway.
About this happening:
Check Point Security Gateways and Security Management Server are affected by two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that can let an...
Check Point Security Gateways and Security Management Server VPN certificate flaws (multiple vulnerabilities)
VulnerabilityHow related: The first flaw, CVE-2026-85102, is a failure to properly validate certificate trust during VPN negotiation. Its CVE record says an unauthenticated remote attacker may be able to run code on the Security Gateway.
About this happening: Check Point Security Gateways and Security Management Server are affected by two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that can let an...
Windows Ancillary Function Driver for WinSock zero-day privilege escalation (CVE-2026-68820)
Vulnerability
H score29
First: 11.08.2026 21:08
Last: 11.08.2026 21:08
Sources 1
About this happening:
CVE-2026-68820 in Windows Ancillary Function Driver for WinSock (AFD.sys) was patched after active exploitation in zero-day attacks, leaving affected Windows syste...
Windows Ancillary Function Driver for WinSock zero-day privilege escalation (CVE-2026-68820)
VulnerabilityAbout this happening: CVE-2026-68820 in Windows Ancillary Function Driver for WinSock (AFD.sys) was patched after active exploitation in zero-day attacks, leaving affected Windows syste...
SmartConsole actively exploited authentication bypass (CVE-2026-16232)
Vulnerability
H score43
First: 23.07.2026 11:13
Last: 23.07.2026 11:13
Sources 1
About this happening:
Check Point addressed CVE-2026-16232, a zero-day authentication bypass in SmartConsole affecting Security Management and Multi-Domain Management products....
SmartConsole actively exploited authentication bypass (CVE-2026-16232)
VulnerabilityAbout this happening: Check Point addressed CVE-2026-16232, a zero-day authentication bypass in SmartConsole affecting Security Management and Multi-Domain Management products....
CISA BOD 26-04 patch directive for CVE-2026-16232
Public Sector Action
H score37
First: 23.07.2026 11:13
Last: 23.07.2026 11:13
Sources 1
About this happening:
CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...
CISA BOD 26-04 patch directive for CVE-2026-16232
Public Sector ActionAbout this happening: CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...
Timeline
-
10.09.2026 14:45 1 articles · 4h ago
Check Point discloses two critical VPN certificate flaws
Initial DisclosureCheck Point disclosed two critical VPN-certificate vulnerabilities affecting Security Gateways and Security Management Server, saying the flaws could let an unauthenticated remote attacker run code under specific conditions and that it had found both issues itself. The company said it had no indication either flaw had been used in an attack.
Show sources
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE — thehackernews.com — 10.09.2026 14:45
-
10.09.2026 14:45 2 articles · 4h ago
Check Point starts Live Patch rollout for VPN certificate flaws
Mitigation Patch UpdateCheck Point began delivering fixes through Live Patch on September 9, 2026 and told customers to install the latest Jumbo Hotfix for their deployed version. A Check Point employee said Live Patch could be installed on top of any Jumbo Hotfix level in R81.20, R82.00 and R82.10, while some R81.10 customers said no Live Patch or Jumbo Hotfix was available for that branch and that mitigation was the only option.
Show sources
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE — thehackernews.com — 10.09.2026 14:45
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE — thehackernews.com — 10.09.2026 14:45