Skip to content
Bellator Cyber Guard
News8 min readStandard

Check Point Patches Critical VPN Flaws Enabling RCE

Check Point patched two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, that could allow remote code execution. Here's what to do.

By Bellator Cyber Guard Security Team

Check Point Ships Fixes for Two Critical VPN Bugs

Check Point Software Technologies has released patches for two critical vulnerabilities in its VPN products, tracked as CVE-2026-85102 and CVE-2026-85103, according to SecurityWeek's report published on September 11, 2026. A Common Vulnerabilities and Exposures (CVE) identifier is a standardized reference number assigned to a publicly disclosed security flaw so vendors, researchers, and defenders can track it consistently across advisories and tools. Both flaws are described as capable of remote code execution (RCE), which is a class of vulnerability that lets an attacker run arbitrary commands on a target system, potentially without needing valid credentials or physical access. Check Point is a network security vendor whose firewall and VPN gateway products are widely deployed by enterprises, government agencies, and managed service providers to secure remote access into corporate networks.

The reported details are limited to the CVE identifiers and the general severity classification. The source material does not specify the affected product lines, whether pre-authentication access is required to trigger the flaws, or whether either vulnerability has already been exploited in the wild. Organizations running Check Point VPN infrastructure should treat that uncertainty as a reason to move quickly rather than wait for further confirmation, since remote access gateways sit at the network perimeter and are a favored entry point for ransomware affiliates and other intrusion actors.

Key Takeaway

Two critical, RCE-capable flaws in Check Point VPN products (CVE-2026-85102 and CVE-2026-85103) now have patches available as of September 2026. VPN gateways are internet-facing by design, so any unpatched RCE flaw in one is a direct path from the open internet into your internal network. Patch on an emergency basis, not on your normal maintenance cycle.

Why Remote Code Execution in a VPN Gateway Is Worse Than It Sounds

Most vulnerability classes require an attacker to already have some foothold, whether that's a user clicking a malicious link or credentials obtained elsewhere. Remote code execution flaws in a VPN gateway remove that requirement. VPN appliances are intentionally exposed to the public internet so that remote employees can connect, which means a working RCE exploit can potentially let an attacker skip credential theft entirely and land directly inside the device that controls network access. Once an attacker controls the VPN gateway itself, they often gain visibility into every subsequent connection that passes through it, along with a stable base for lateral movement into internal systems.

This pattern is not new. Edge devices, including VPN concentrators, firewalls, and secure web gateways, have been a consistent target for both opportunistic and state-linked threat actors over the past several years precisely because a single exploited device can expose an entire organization's remote access infrastructure. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has repeatedly flagged edge device exploitation as a leading initial access vector in its advisories, and CISA's Known Exploited Vulnerabilities (KEV) catalog tracks flaws, including past VPN vulnerabilities, that have been confirmed as actively exploited. Whether or not CVE-2026-85102 or CVE-2026-85103 end up on that list, the underlying risk profile of an unpatched, internet-facing VPN gateway is the same: it is a high-value target sitting in plain sight.

What Healthcare Practices, Tax Firms, and Small Businesses Should Do Now

Bellator Cyber Guard's guidance for organizations running Check Point VPN infrastructure is straightforward: treat this as an emergency patch, not a routine update. The following steps apply whether you manage this infrastructure directly or rely on a managed service provider (MSP) or managed security service provider (MSSP):

  • Identify your exposure first. Confirm which Check Point products and software versions are running in your environment, including any remote access VPN gateways, before assuming you are or are not affected. If a third party manages your firewall or VPN, ask them directly whether the affected products are in use and when patching will be complete.
  • Apply vendor patches on an accelerated timeline. For internet-facing infrastructure like a VPN gateway, the standard advice to test patches in a staging environment before production rollout should be compressed as much as your change management process allows. The exposure window between a public disclosure and the first exploitation attempts against edge devices has repeatedly been measured in days, not weeks.
  • Review VPN access logs for anomalies. Look for unusual login times, unfamiliar source IP addresses, or authentication attempts from geographies your organization doesn't normally operate in, both before and after patching, since a compromise that predates the patch would not be remediated by the update alone.
  • Enforce multi-factor authentication (MFA) on all VPN accounts. MFA does not prevent every RCE exploitation path, but it substantially raises the difficulty for an attacker trying to pair a technical exploit with credential-based access, and it remains one of the highest-value controls for any remote access system.
  • Segment what the VPN gateway can reach. If your network architecture allows a compromised VPN device to reach every internal system without restriction, that is a separate, structural risk worth addressing regardless of this specific advisory. Limiting the gateway's access to only the resources remote users actually need reduces the blast radius of any future gateway compromise.

For regulated organizations, including HIPAA-covered healthcare practices and firms handling federal tax data under IRS Publication 4557 safeguards, an unpatched, internet-facing RCE vulnerability in remote access infrastructure is the kind of gap that auditors and cyber insurers increasingly ask about directly. Documenting when the patch was identified, tested, and deployed, along with any compensating controls applied in the interim, is worth doing now rather than reconstructing after the fact.

What Remains Unclear

The publicly available reporting on CVE-2026-85102 and CVE-2026-85103 does not, at this time, specify the exact Check Point product lines affected, the attack complexity, or whether authentication is required to exploit either flaw. It also does not confirm whether either vulnerability has been used in real-world attacks. Organizations should consult Check Point's own security advisories directly for the authoritative list of affected versions and remediation steps, since vendor advisories are typically updated as more detail becomes available. Bellator Cyber Guard will continue to track developments on these two vulnerabilities and update guidance if exploitation activity is confirmed.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

See whether the service fits

Choose a security approach that fits the way you already work

Start with the outcome and scope. A good fit is clear about who it is for, what is covered, how implementation works, and what happens when the service detects a problem.

People also look for

Keep exploring Network & cloud security

Protect the connections, cloud accounts, and remote-work paths that people rely on every day.