Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE Swati KhandelwalSep 10, 2026Vulnerability / Network Security Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security Management Server, the console used to configure them. Check Point disclosed the flaws on September 9 in a notice to its customer community, and began delivering fixes the same day. The company says it found both itself and has no indication that either…
CVEs: CVE-2026-85102, CVE-2026-85103, CVE-2026-50751, CVE-2026-16232
Original source: thehackernews.com