Check Point Issues Patches for Two Critical VPN Bugs Enabling Unauthenticated Remote Code Execution
Check Point Software said it has issued security patches for a pair of recently disclosed VPN flaws, catalogued as CVE-2026-85102 and CVE-2026-85103, both receiving a top‑tier CVSS rating of 9.8. These weaknesses can be exploited without credentials and may allow remote code execution in specific scenarios, leading the company to classify them as critical.
Both issues reside in Check Point’s Remote Access VPN product. The advisory explains that they arise from mishandling of network packets that can be fashioned to evade standard security validations, thereby enabling an attacker to inject and execute arbitrary code on the affected device. While the two CVEs follow a comparable attack route, each targets a different code path inside the VPN service.
Enterprises rely heavily on virtual private networks to protect remote access, a need that has grown with enduring hybrid‑work arrangements. An RCE flaw in a VPN gateway can grant adversaries the means to breach network perimeters, steal data, or install further malicious payloads. A 9.8 severity score situates these bugs just shy of the maximum rating, underscoring their high impact and the fact that no credentials are needed.
Check Point strongly recommends that customers install the released patches without delay. The updates have been posted through the vendor’s usual firmware distribution mechanisms, and the security team advises confirming that every VPN appliance is operating the newest version. Entities that have not yet applied the fixes should examine network logs for irregular traffic that might signal exploitation attempts.
This revelation highlights the persistent difficulty of keeping remote‑access systems secure. Analysts observe that VPN flaws have emerged repeatedly over the past years, emphasizing the importance of constant monitoring and swift patching. As the updates are deployed, security teams are expected to evaluate the extent of impacted installations and may implement further hardening steps to curb future threats.
Comments (0)
Be the first to comment.
Join the discussion