Severity Daily

IT and AI security incidents, checked against the primary source

Tag: CVE-2026-85103

  • Check Point’s two 9.8 VPN flaws are scoped by hotfix take number, and its own CVE records leave out Spark

    Check Point’s two 9.8 VPN flaws are scoped by hotfix take number, and its own CVE records leave out Spark

    Both flaws let an unauthenticated attacker run code on a perimeter appliance, and neither CVE record names a fixed version — the affected boundary is a Jumbo Hotfix take number, and the Spark appliance line that Check Point’s advisories cover does not appear in the records at all.

    What happened

    Check Point published CVE-2026-85102 and CVE-2026-85103 through its own CNA on September 9, 2026, at 1:20 p.m. UTC, and its support advisories followed on September 10, 2026. CERT-EU issued advisory 2026-012 covering both the same day. Both flaws are rated 9.8 and both allow remote code execution without authentication. Severity Daily did not cover the disclosure when it landed; this page is written three days late and says so.

    What is new here is not the disclosure. It is what the records say when you read them next to the advisories, which is the exercise nobody performs in the first twenty-four hours.

    CVE-2026-85102 is described in the record as “Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.” It is CWE-295, improper certificate validation, with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. CVE-2026-85103 is “A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.” That one is CWE-122, with the same vector and the same 9.8.

    Both scores come from [email protected]. Check Point is the CNA for its own products, so the vendor wrote the description, chose the weakness class, and set the score. There is no second opinion in either record and no CISA-ADP enrichment on either. Neither carries cisaExploitAdd.

    The versions are not versions

    The affected-product data in both records reads the same way, and it is unusual enough to stop on. There is no “fixed in” release. What the configurations give is three lines: R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, and R81.20 with Jumbo Hotfix Take 165 or below.

    A Jumbo Hotfix Accumulator take is a rolling patch bundle, not a release. Two gateways can both report R82 and sit on opposite sides of this flaw, because one is on Take 120 and the other on Take 130. Nothing in the version string an inventory system collects answers the question. The answer lives in a number an operator has to pull from the appliance, and asset databases built around product-and-version pairs generally do not carry it.

    This is not Check Point being careless. It is an accurate description of how the product is patched, expressed in a record format built for software that ships versions. But the practical effect is that the standard vulnerability-management pipeline — match CPE, compare version, produce a finding — cannot produce a correct answer for these two CVEs, and will either miss appliances or flag patched ones.

    Spark is in the advisories and not in the records

    The larger gap is a product line. Both CVE records name Quantum Security Gateway; CVE-2026-85103 additionally names Quantum Security Management. Neither record mentions Spark, Check Point’s small-office and branch appliance line.

    Check Point’s advisories do. CERT-EU’s 2026-012, reading sk1000117 and sk1000118, lists Security Gateway, Security Management Server, and Spark Firewall as affected. Reporting from SecurityWeek on September 11, quoting the same advisories, gives CVE-2026-85102 as affecting “Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN” and CVE-2026-85103 as affecting “Check Point Security Management Server, Security Gateway, and Spark Firewall.”

    We could not read sk1000117 or sk1000118 ourselves — support.checkpoint.com is disallowed to automated readers — so the advisory scope above is reported at one remove, and we are flagging it as such rather than presenting it as vendor language we verified. But two independent readers of those advisories both came away with Spark on the list, and the CVE records the same vendor authored do not have it.

    The reason that ordering matters is the workaround. Per the same reporting, Check Point’s mitigation for organizations that cannot patch immediately is to “disable implied rules for VPN and manually define VPN access for UDP/500 and UDP/4500 for the specific peer IP addresses” — and that mitigation is said not to apply to locally managed Spark instances, which are told instead to take “the latest Jumbo hotfixes as soon as possible.”

    So the appliance line that is missing from the machine-readable record is the same line that has no workaround, and it is the line most likely to be sitting on a branch-office internet connection with nobody watching its hotfix level. A defender who scopes this incident from the CVE records will conclude that Spark is not in play. A defender who reads the advisory will conclude the opposite, and will also learn that Spark is the case with the fewest options.

    Why it matters

    Check Point says it found both flaws itself and has no evidence either has been exploited. That is worth stating plainly, because it is the difference between this story and an emergency: as of publication there is no exploitation, no KEV listing, no federal deadline, and no public proof-of-concept we could find. Internally discovered, internally reported, patched before disclosure — this is the disclosure process working.

    The failure is downstream, in the handoff from advisory to record. A vulnerability’s advisory is prose written for humans who already run the product. Its CVE record is structured data consumed by scanners, ticketing systems, and vendor-risk questionnaires that will still be asking about it in eighteen months. When the two disagree about which products are affected, the record wins by default, because the record is what gets queried. Nobody re-reads sk1000117 in March.

    There is also a detail in the reporting worth carrying, if it holds. Check Point reportedly clarified that CVE-2026-85103 could, in theory, be triggered in an environment with no VPN in use but with VPN certificates present. If that is right, “we don’t run VPN on that gateway” is not a scoping answer for the heap overflow, only for the certificate-trust flaw. Nothing in either CVE record captures that distinction — both records simply say VPN certificate handling — so an operator working from the record alone would reasonably exclude non-VPN gateways from both.

    This is the same shape this publication has been finding all week in unrelated products: the authoritative machine-readable artifact covers less than the human-readable one. It showed up in a fix that shipped for one branch and not another, in a catalog entry covering two links of a three-link chain, and now in a product line that exists in the advisory and not in the record.

    What to do

    Determine the Jumbo Hotfix take on every Check Point gateway, management server, and Spark appliance, not the release. Anything at R82.10 Take 43 or below, R82 Take 125 or below, or R81.20 Take 165 or below is affected by both flaws.

    Apply the current Jumbo Hotfix for the branch. Systems with LivePatch enabled are reported to receive the fix automatically, which is worth verifying rather than assuming.

    Do not scope Spark out on the basis of the CVE records. Treat Spark as affected, and note that the implied-rules workaround is reported not to cover locally managed Spark instances.

    If patching has to wait, the reported interim step is to disable implied rules for VPN and define VPN access explicitly for UDP/500 and UDP/4500 to known peer addresses. Confirm the exact wording against sk1000117 and sk1000118 before making the change; we could not read those pages.

    Sourcing note

    Checked: the NVD records for CVE-2026-85102 (published 2026-09-09T13:20:43.793, last modified 2026-09-10T04:18:18.243) and CVE-2026-85103 (published 2026-09-09T13:20:43.997, last modified 2026-09-10T04:18:18.390), both sourced to [email protected]; and CERT-EU security advisory 2026-012, dated September 10, 2026, which recommends “applying the available hotfixes as soon as possible, prioritising internet-facing and perimeter appliances.”

    Could not reach: support.checkpoint.com, which is disallowed to automated fetching, so sk1000117 and sk1000118 were not read directly. Every statement in this story about advisory scope, the implied-rules workaround, the Spark exclusion, LivePatch behavior, and Check Point’s exploitation position is attributed to CERT-EU’s advisory or to SecurityWeek’s and The Hacker News’s reporting of those pages, not to language we verified at source.

    Unresolved: whether Check Point intends to add Spark Firewall to the CVE records, and whether the heap overflow really is reachable on a gateway with certificates but no VPN in use. Both would change how the flaws should be scoped, and neither can be settled without the vendor advisories.