Check Point has patched two critical vulnerabilities in how its firewall and management products handle VPN certificates. Both carry a CVSS score of 9.8 and could let an unauthenticated remote attacker run code, though the vendor says only under specific conditions it has not described.
The flaws, CVE-2026-85102 and CVE-2026-85103, were disclosed to Check Point’s customer community on September 9, with fixes shipping the same day. The first is a failure to validate certificate trust during VPN negotiation. The second is a heap-based buffer overflow triggered while decoding the ASN.1 structure of a VPN certificate. Check Point says it found both itself and has no indication of exploitation.
Affected versions include R82.10 with Jumbo Hotfix Take 43 or below, R82 with Take 125 or below, and R81.20 with Take 165 or below. Canada’s cyber security center published a broader product list without version details.
Healthcare networks lean heavily on remote-access gateways, and edge appliances remain among the most exploited entry points into hospital environments. An unauthenticated flaw on the device that terminates clinician and vendor VPN sessions sits directly in front of clinical systems.
Administrators should identify which Quantum branches and hotfix takes they run, apply the patches promptly, and keep the management console off the public internet. Until appliances are updated, monitoring for unusual VPN negotiation attempts and certificate-parsing crashes is worth prioritizing.