Check Point VPN certificate security patch release (CVE-2026-85102, CVE-2026-85103)
Security Patch Release
Summary
Hide ▲
Show ▼
Check Point began delivering fixes on September 9 for CVE-2026-85102 and CVE-2026-85103, two critical VPN certificate flaws in Security Gateways and Security Management Server. The release addresses unauthenticated remote code execution risk and gives customers remediation through Check Point Live Patch or the latest Jumbo Hotfix. Affected deployments include R82.10 / Jumbo Hotfix Take 43 or below, R82 / Take 125 or below, and R81.20 / Take 165 or below. Check Point says it found both issues itself and has no indication of attack use.
Related Happenings
Check Point VPN certificate mitigation guidance
Advisory/Mitigation
H score53
First: 10.09.2026 14:45
Last: 10.09.2026 14:45
Sources 1
How related:
Check Point gave customers two routes to the fix. The first is Check Point Live Patch. The company says customers using it are protected automatically as the rollout begins, which started on September 9.
About this happening:
Check Point directed affected customers to Live Patch or the latest Jumbo Hotfix for its VPN certificate flaws, with rollout beginning on September 9. The guidance...
Check Point VPN certificate mitigation guidance
Advisory/MitigationHow related: Check Point gave customers two routes to the fix. The first is Check Point Live Patch. The company says customers using it are protected automatically as the rollout begins, which started on September 9.
About this happening: Check Point directed affected customers to Live Patch or the latest Jumbo Hotfix for its VPN certificate flaws, with rollout beginning on September 9. The guidance...
HPE ArubaOS-CX security bulletin (CVE-2026-73749)
Security Patch Release
H score31
First: 03.09.2026 21:28
Last: 03.09.2026 21:28
Sources 1
About this happening:
HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code...
HPE ArubaOS-CX security bulletin (CVE-2026-73749)
Security Patch ReleaseAbout this happening: HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code...
Paperclip security patch release for CVE-2026-41679
Security Patch Release
H score45
First: 05.08.2026 17:30
Last: 05.08.2026 17:30
Sources 1
About this happening:
Paperclip shipped 2026.416.0 and 0.3.1 to close three disclosed vulnerabilities that could expose data and enable unauthenticated command execution. The releas...
Paperclip security patch release for CVE-2026-41679
Security Patch ReleaseAbout this happening: Paperclip shipped 2026.416.0 and 0.3.1 to close three disclosed vulnerabilities that could expose data and enable unauthenticated command execution. The releas...
N-able security patch release for CVE-2026-18577
Security Patch Release
H score46
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
N-able security patch release for CVE-2026-18577
Security Patch ReleaseAbout this happening: N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
OpenWrt security patch release for CVE-2026-53921
Security Patch Release
H score37
First: 28.07.2026 15:56
Last: 28.07.2026 15:56
Sources 1
About this happening:
OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...
OpenWrt security patch release for CVE-2026-53921
Security Patch ReleaseAbout this happening: OpenWrt released 24.10.8 and 25.12.5 to close a critical DHCPv6 stack overflow in odhcpd, reducing the risk of root code execution on exposed routers. The...
Timeline
-
09.09.2026 03:00 2 articles · 1d ago
Check Point discloses two critical VPN certificate flaws and begins same-day fixes
Initial DisclosureCheck Point disclosed CVE-2026-85102 and CVE-2026-85103 on September 9, saying the critical VPN certificate flaws could let an unauthenticated remote attacker run code on Security Gateways and Security Management Server systems under unspecified conditions while fixes began rolling out the same day.
Show sources
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE — thehackernews.com — 10.09.2026 14:45
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE — thehackernews.com — 10.09.2026 14:45
-
09.09.2026 03:00 1 articles · 1d ago
Check Point details certificate trust validation failure and ASN.1 buffer overflow in VPN handling
Technical Analysis UpdateCheck Point described CVE-2026-85102 as a failure to properly validate certificate trust during VPN negotiation and CVE-2026-85103 as a heap-based buffer overflow while decoding the ASN.1 structure of a VPN certificate, with the CVE records tying the issues to Security Gateway and Quantum Security Management and Security Gateway systems.
Show sources
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE — thehackernews.com — 10.09.2026 14:45