Find notable cyber news and cases, enriched with sources, timelines, and signals.

Check Point VPN certificate security patch release (CVE-2026-85102, CVE-2026-85103)

Security Patch Release
First reported
Last updated
Happening score
H score 53
1 unique sources, 1 articles

Summary

Hide ▲

Check Point began delivering fixes on September 9 for CVE-2026-85102 and CVE-2026-85103, two critical VPN certificate flaws in Security Gateways and Security Management Server. The release addresses unauthenticated remote code execution risk and gives customers remediation through Check Point Live Patch or the latest Jumbo Hotfix. Affected deployments include R82.10 / Jumbo Hotfix Take 43 or below, R82 / Take 125 or below, and R81.20 / Take 165 or below. Check Point says it found both issues itself and has no indication of attack use.

Related Happenings

Check Point VPN certificate mitigation guidance

Advisory/Mitigation
H score53 First: 10.09.2026 14:45 Last: 10.09.2026 14:45 Sources 1

How related: Check Point gave customers two routes to the fix. The first is Check Point Live Patch. The company says customers using it are protected automatically as the rollout begins, which started on September 9.

About this happening: Check Point directed affected customers to Live Patch or the latest Jumbo Hotfix for its VPN certificate flaws, with rollout beginning on September 9. The guidance...

HPE ArubaOS-CX security bulletin (CVE-2026-73749)

Security Patch Release
H score31 First: 03.09.2026 21:28 Last: 03.09.2026 21:28 Sources 1

About this happening: HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code...

Paperclip security patch release for CVE-2026-41679

Security Patch Release
H score45 First: 05.08.2026 17:30 Last: 05.08.2026 17:30 Sources 1

About this happening: Paperclip shipped 2026.416.0 and 0.3.1 to close three disclosed vulnerabilities that could expose data and enable unauthenticated command execution. The releas...

N-able security patch release for CVE-2026-18577

Security Patch Release
H score46 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

About this happening: N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...

OpenWrt security patch release for CVE-2026-53921

Security Patch Release
H score37 First: 28.07.2026 15:56 Last: 28.07.2026 15:56 Sources 1

About this happening: OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...

Timeline

  1. 09.09.2026 03:00 2 articles · 1d ago

    Check Point discloses two critical VPN certificate flaws and begins same-day fixes

    Initial Disclosure

    Check Point disclosed CVE-2026-85102 and CVE-2026-85103 on September 9, saying the critical VPN certificate flaws could let an unauthenticated remote attacker run code on Security Gateways and Security Management Server systems under unspecified conditions while fixes began rolling out the same day.

    Show sources
  2. 09.09.2026 03:00 1 articles · 1d ago

    Check Point details certificate trust validation failure and ASN.1 buffer overflow in VPN handling

    Technical Analysis Update

    Check Point described CVE-2026-85102 as a failure to properly validate certificate trust during VPN negotiation and CVE-2026-85103 as a heap-based buffer overflow while decoding the ASN.1 structure of a VPN certificate, with the CVE records tying the issues to Security Gateway and Quantum Security Management and Security Gateway systems.

    Show sources