Find notable cyber news and cases, enriched with sources, timelines, and signals.

Check Point VPN certificate mitigation guidance

Advisory/Mitigation
First reported
Last updated
Happening score
H score 53
1 unique sources, 1 articles

Summary

Hide ▲

Check Point directed affected customers to Live Patch or the latest Jumbo Hotfix for its VPN certificate flaws, with rollout beginning on September 9. The guidance matters because some deployments could not patch immediately and had to rely on mitigation steps instead.

Related Happenings

Check Point VPN certificate security patch release (CVE-2026-85102, CVE-2026-85103)

Security Patch Release
H score53 First: 10.09.2026 14:45 Last: 10.09.2026 14:45 Sources 1

How related: Check Point disclosed the flaws on September 9 in a notice to its customer community, and began delivering fixes the same day.

About this happening: Check Point began delivering fixes on September 9 for CVE-2026-85102 and CVE-2026-85103, two critical VPN certificate flaws in Security Gateways and Secu...

Check Point Security Gateways and Security Management Server VPN certificate flaws (multiple vulnerabilities)

Vulnerability
H score53 First: 10.09.2026 14:45 Last: 10.09.2026 14:45 Sources 1

How related: The first flaw, CVE-2026-85102, is a failure to properly validate certificate trust during VPN negotiation. Its CVE record says an unauthenticated remote attacker may be able to run code on the Security Gateway.

About this happening: Check Point Security Gateways and Security Management Server are affected by two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that can let an...

Windows Ancillary Function Driver for WinSock zero-day privilege escalation (CVE-2026-68820)

Vulnerability
H score29 First: 11.08.2026 21:08 Last: 11.08.2026 21:08 Sources 1

About this happening: CVE-2026-68820 in Windows Ancillary Function Driver for WinSock (AFD.sys) was patched after active exploitation in zero-day attacks, leaving affected Windows syste...

SmartConsole actively exploited authentication bypass (CVE-2026-16232)

Vulnerability
H score43 First: 23.07.2026 11:13 Last: 23.07.2026 11:13 Sources 1

About this happening: Check Point addressed CVE-2026-16232, a zero-day authentication bypass in SmartConsole affecting Security Management and Multi-Domain Management products....

CISA BOD 26-04 patch directive for CVE-2026-16232

Public Sector Action
H score37 First: 23.07.2026 11:13 Last: 23.07.2026 11:13 Sources 1

About this happening: CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...

Timeline

  1. 10.09.2026 14:45 1 articles · 4h ago

    Check Point discloses two critical VPN certificate flaws

    Initial Disclosure

    Check Point disclosed two critical VPN-certificate vulnerabilities affecting Security Gateways and Security Management Server, saying the flaws could let an unauthenticated remote attacker run code under specific conditions and that it had found both issues itself. The company said it had no indication either flaw had been used in an attack.

    Show sources
  2. 10.09.2026 14:45 2 articles · 4h ago

    Check Point starts Live Patch rollout for VPN certificate flaws

    Mitigation Patch Update

    Check Point began delivering fixes through Live Patch on September 9, 2026 and told customers to install the latest Jumbo Hotfix for their deployed version. A Check Point employee said Live Patch could be installed on top of any Jumbo Hotfix level in R81.20, R82.00 and R82.10, while some R81.10 customers said no Live Patch or Jumbo Hotfix was available for that branch and that mitigation was the only option.

    Show sources