Severity Daily

IT and AI security incidents, checked against the primary source

Tag: Check Point

  • Two Monday deadlines outrank a day of nines and a seventeen-record batch

    Two Monday deadlines outrank a day of nines and a seventeen-record batch

    Eleven stories ran today, and the loudest of them were loud on the numbers: a 10.0, two 9.9s, a pair of 9.8s on a perimeter VPN appliance, and seventeen CVE records for one project landing in the same minute. None of that is what to deal with first. Two flaws already on CISA’s Known Exploited Vulnerabilities catalog come due Monday, September 14 — ConnectWise ScreenConnect and GitLab — and both carry BOD 26-04’s forensic-triage obligation, which means a federal agency has to remediate inside the window and also determine whether the asset was already compromised. That is about 48 hours, on the weekend, and it is the only thing on today’s wire with a clock attached. A 9.8 with a patch available can wait until Monday morning; these two cannot. The ScreenConnect item is also the one most likely to be misread: the flaw is in the client, not the server, so cloud-hosted customers told “no action is required” for their server still have to update every host client and access agent they run.

    The day had a thread, and it was GitLab. One patch release, September 10, produced three separate stories in eighteen hours, and the vendor supplied none of the new facts in any of them. Overnight, the CISA coordinator block attached to the NVD record marked exploitation “active” while GitLab’s own advisory said nothing about exploitation at all. By the afternoon the catalog itself carried Thursday’s addition and Monday’s deadline — a date this site declined to report twelve hours earlier and has since corrected on the story that got it wrong. And by evening the record for a second flaw in the same release, CVE-2026-87719, named the two things the release notes had left out: the entry condition is an authenticated user with Duo Chat access, not an administrator, and what they come away with is Advanced Search instance configurations and credentials.

    After the deadlines, the perimeter. Check Point’s two 9.8s let an unauthenticated attacker run code on a VPN appliance, and neither record names a fixed version — the boundary is a Jumbo Hotfix take number, and the Spark appliance line the advisories cover is missing from the records entirely. Frontegg SAML SSO accepts unsigned SAML responses at 9.8 with no fix at all, the plugin having been closed on WordPress.org on September 4. The Events Calendar took three releases to close two unauthenticated 9.8 remote code execution flaws on a plugin installed on more than 600,000 sites, and no changelog line says so.

    Below that, three records that describe a flaw better than they describe a remedy. AVideo’s seventeen all draw the affected line at the same git commit hash, with the last tagged release dating to April 2024. vLLM and Socket Firewall make an unflattering pair, because in both the thing that failed was the safeguard: a trust_remote_code flag that vanished into **kwargs, and a firewall that did not verify TLS to the registries it exists to police. Flatpak’s Critical sandbox escape waited 32 days for an identifier, and the one Flatpak CVE issued in the meantime was a different bug.

    Still open at the end of the day: NVD’s record for the GitLab 10.0 does not carry cisaExploitAdd or cisaActionDue, so the single most authoritative machine-readable source an operator is likely to query still does not say the flaw is on KEV with a deadline two days out. GitLab has said nothing about exploitation since the patch release. Frontegg has no fixed version to offer, AVideo has no release to upgrade to, and Check Point’s records still omit Spark.

  • Check Point’s two 9.8 VPN flaws are scoped by hotfix take number, and its own CVE records leave out Spark

    Check Point’s two 9.8 VPN flaws are scoped by hotfix take number, and its own CVE records leave out Spark

    Both flaws let an unauthenticated attacker run code on a perimeter appliance, and neither CVE record names a fixed version — the affected boundary is a Jumbo Hotfix take number, and the Spark appliance line that Check Point’s advisories cover does not appear in the records at all.

    What happened

    Check Point published CVE-2026-85102 and CVE-2026-85103 through its own CNA on September 9, 2026, at 1:20 p.m. UTC, and its support advisories followed on September 10, 2026. CERT-EU issued advisory 2026-012 covering both the same day. Both flaws are rated 9.8 and both allow remote code execution without authentication. Severity Daily did not cover the disclosure when it landed; this page is written three days late and says so.

    What is new here is not the disclosure. It is what the records say when you read them next to the advisories, which is the exercise nobody performs in the first twenty-four hours.

    CVE-2026-85102 is described in the record as “Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.” It is CWE-295, improper certificate validation, with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. CVE-2026-85103 is “A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.” That one is CWE-122, with the same vector and the same 9.8.

    Both scores come from [email protected]. Check Point is the CNA for its own products, so the vendor wrote the description, chose the weakness class, and set the score. There is no second opinion in either record and no CISA-ADP enrichment on either. Neither carries cisaExploitAdd.

    The versions are not versions

    The affected-product data in both records reads the same way, and it is unusual enough to stop on. There is no “fixed in” release. What the configurations give is three lines: R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, and R81.20 with Jumbo Hotfix Take 165 or below.

    A Jumbo Hotfix Accumulator take is a rolling patch bundle, not a release. Two gateways can both report R82 and sit on opposite sides of this flaw, because one is on Take 120 and the other on Take 130. Nothing in the version string an inventory system collects answers the question. The answer lives in a number an operator has to pull from the appliance, and asset databases built around product-and-version pairs generally do not carry it.

    This is not Check Point being careless. It is an accurate description of how the product is patched, expressed in a record format built for software that ships versions. But the practical effect is that the standard vulnerability-management pipeline — match CPE, compare version, produce a finding — cannot produce a correct answer for these two CVEs, and will either miss appliances or flag patched ones.

    Spark is in the advisories and not in the records

    The larger gap is a product line. Both CVE records name Quantum Security Gateway; CVE-2026-85103 additionally names Quantum Security Management. Neither record mentions Spark, Check Point’s small-office and branch appliance line.

    Check Point’s advisories do. CERT-EU’s 2026-012, reading sk1000117 and sk1000118, lists Security Gateway, Security Management Server, and Spark Firewall as affected. Reporting from SecurityWeek on September 11, quoting the same advisories, gives CVE-2026-85102 as affecting “Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN” and CVE-2026-85103 as affecting “Check Point Security Management Server, Security Gateway, and Spark Firewall.”

    We could not read sk1000117 or sk1000118 ourselves — support.checkpoint.com is disallowed to automated readers — so the advisory scope above is reported at one remove, and we are flagging it as such rather than presenting it as vendor language we verified. But two independent readers of those advisories both came away with Spark on the list, and the CVE records the same vendor authored do not have it.

    The reason that ordering matters is the workaround. Per the same reporting, Check Point’s mitigation for organizations that cannot patch immediately is to “disable implied rules for VPN and manually define VPN access for UDP/500 and UDP/4500 for the specific peer IP addresses” — and that mitigation is said not to apply to locally managed Spark instances, which are told instead to take “the latest Jumbo hotfixes as soon as possible.”

    So the appliance line that is missing from the machine-readable record is the same line that has no workaround, and it is the line most likely to be sitting on a branch-office internet connection with nobody watching its hotfix level. A defender who scopes this incident from the CVE records will conclude that Spark is not in play. A defender who reads the advisory will conclude the opposite, and will also learn that Spark is the case with the fewest options.

    Why it matters

    Check Point says it found both flaws itself and has no evidence either has been exploited. That is worth stating plainly, because it is the difference between this story and an emergency: as of publication there is no exploitation, no KEV listing, no federal deadline, and no public proof-of-concept we could find. Internally discovered, internally reported, patched before disclosure — this is the disclosure process working.

    The failure is downstream, in the handoff from advisory to record. A vulnerability’s advisory is prose written for humans who already run the product. Its CVE record is structured data consumed by scanners, ticketing systems, and vendor-risk questionnaires that will still be asking about it in eighteen months. When the two disagree about which products are affected, the record wins by default, because the record is what gets queried. Nobody re-reads sk1000117 in March.

    There is also a detail in the reporting worth carrying, if it holds. Check Point reportedly clarified that CVE-2026-85103 could, in theory, be triggered in an environment with no VPN in use but with VPN certificates present. If that is right, “we don’t run VPN on that gateway” is not a scoping answer for the heap overflow, only for the certificate-trust flaw. Nothing in either CVE record captures that distinction — both records simply say VPN certificate handling — so an operator working from the record alone would reasonably exclude non-VPN gateways from both.

    This is the same shape this publication has been finding all week in unrelated products: the authoritative machine-readable artifact covers less than the human-readable one. It showed up in a fix that shipped for one branch and not another, in a catalog entry covering two links of a three-link chain, and now in a product line that exists in the advisory and not in the record.

    What to do

    Determine the Jumbo Hotfix take on every Check Point gateway, management server, and Spark appliance, not the release. Anything at R82.10 Take 43 or below, R82 Take 125 or below, or R81.20 Take 165 or below is affected by both flaws.

    Apply the current Jumbo Hotfix for the branch. Systems with LivePatch enabled are reported to receive the fix automatically, which is worth verifying rather than assuming.

    Do not scope Spark out on the basis of the CVE records. Treat Spark as affected, and note that the implied-rules workaround is reported not to cover locally managed Spark instances.

    If patching has to wait, the reported interim step is to disable implied rules for VPN and define VPN access explicitly for UDP/500 and UDP/4500 to known peer addresses. Confirm the exact wording against sk1000117 and sk1000118 before making the change; we could not read those pages.

    Sourcing note

    Checked: the NVD records for CVE-2026-85102 (published 2026-09-09T13:20:43.793, last modified 2026-09-10T04:18:18.243) and CVE-2026-85103 (published 2026-09-09T13:20:43.997, last modified 2026-09-10T04:18:18.390), both sourced to [email protected]; and CERT-EU security advisory 2026-012, dated September 10, 2026, which recommends “applying the available hotfixes as soon as possible, prioritising internet-facing and perimeter appliances.”

    Could not reach: support.checkpoint.com, which is disallowed to automated fetching, so sk1000117 and sk1000118 were not read directly. Every statement in this story about advisory scope, the implied-rules workaround, the Spark exclusion, LivePatch behavior, and Check Point’s exploitation position is attributed to CERT-EU’s advisory or to SecurityWeek’s and The Hacker News’s reporting of those pages, not to language we verified at source.

    Unresolved: whether Check Point intends to add Spark Firewall to the CVE records, and whether the heap overflow really is reachable on a gateway with certificates but no VPN in use. Both would change how the flaws should be scoped, and neither can be settled without the vendor advisories.