Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for critical Check Point VPN vulnerabilities CVE-2026-85102 and CVE-2026-85103 rated CVSS 9.8 allowing unauthenticated remote code execution — patch now

Critical Check Point VPN Flaws Rated 9.8 — Patch or Mitigate Today

Check Point has disclosed and patched two critical VPN vulnerabilities — CVE-2026-85102 and CVE-2026-85103 — both rated CVSS 9.8 out of 10. Either flaw lets an unauthenticated attacker execute code on your firewall remotely.

The first bug exploits improper certificate validation during VPN negotiation. The second is a heap overflow in the VPN certificate parser. Both affect Check Point Security Gateways, Management Servers, and Spark Firewalls running R81.20, R82, and R82.10. The Dutch NCSC has warned of imminent exploitation and is urging immediate remediation.

Why this matters for Australian businesses

This is the third time in 2026 that a major firewall vendor has shipped critical VPN patches — SonicWall and Fortinet both faced similar zero-days earlier this year. Across our Australian client base, we keep seeing the same pattern: VPN appliances are now the number-one target for ransomware initial access. Qilin specifically exploited an earlier Check Point VPN bug just months ago.

If your business runs a Check Point gateway — common in Australian financial services, legal, and professional services firms — treat this as urgent.

What to do right now

Patch immediately. Install the latest Jumbo Hotfix: R82.10 Take 44+, R82 Take 126+, or R81.20 Take 166+.

If you can’t patch yet, disable implied VPN rules for Site-to-Site connections and lock UDP ports 500 and 4500 to known peer IPs only. This workaround doesn’t cover Remote Access VPN.

Check whether Live Patch is enabled. If it is, the fix rolled out automatically from 9 September.

Not sure whether you’re affected? Contact All IT Services — we can audit your firewall exposure and confirm your VPN configuration is locked down. If you’re running a managed security arrangement with us, we’ve already applied the patches across all managed Check Point environments.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →