Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

Executive Summary

Check Point has patched two critical vulnerabilities in its firewall and management products that mishandle VPN certificates. The flaws, rated 9.8 on CVSS, could allow an unauthenticated attacker to execute remote code on Security Gateways and Management servers under specific, undisclosed conditions. The company has released patches and urged customers to update.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-10T11:45:05+00:00 - Category: threat-intel

Original Description: Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security

"A rolling stone gathers no moss."

— Publilius Syrus
Source: The Hacker News