CVE-2026-85102 and CVE-2026-85103 concern specific Check Point enterprise security products used for company remote access and network connections. A headline about a VPN flaw does not establish that every consumer VPN app is affected. The relevant question is which Check Point product, build and configuration an organization operates.
Reviewed September 15, 2026. CERT-EU’s advisory describes the affected enterprise products and remediation. If you connect to a company network that uses Check Point, its administrator needs to check the exact product and build against the vendor’s current guidance. FindMyIP cannot establish whether a remote gateway is vulnerable or patched.
What was disclosed (high level)
Around 9 September 2026, two Check Point advisories landed as CVE-2026-85102 and CVE-2026-85103. CERT-EU lists both at CVSS 9.8 — critical — with unauthenticated remote code execution risk on affected appliances that expose VPN features.
Short, hedged summary of the public descriptions:
- CVE-2026-85102: Check Point advisory — improper certificate validation during VPN negotiation on Security Gateway / Spark when Site-to-Site or Remote Access VPN is in play.
- CVE-2026-85103: Check Point advisory — a heap overflow in VPN certificate ASN.1 decoding. It can also affect Security Management Server, not only the gateway.
That is enough for a normal reader. We are not walking through negotiation, payloads, or how to reproduce anything. Patch status belongs with the people who own the boxes.
Exploitation reporting can change after disclosure. Do not interpret the absence of a reported incident as proof that an exposed device is safe; consult the dated vendor and national-security advisories when deciding remediation priority.
Who is actually in scope
These CVEs are about enterprise kit, not “any app with VPN in the name.”
Public materials point at families such as:
- Quantum Security Gateway and Spark (VPN-related paths for both CVEs)
- For CVE-2026-85103, also Security Management
- Version lines often discussed: R81.20, R82, R82.10 — with fixes via Jumbo Hotfix / builds below the fixed ones needing updates
- The vendor’s current affected-version table identifies exclusions such as R82.20; verify the exact product and build rather than relying on a version-family summary
Exact build matrix changes as vendors ship Hotfixes and LivePatch. If you are an admin, read Check Point’s advisory for your train. If you are not an admin, you do not need the build table.
Temporary mitigation for some Site-to-Site setups (restrict UDP 500/4500 to known peers) is an ops control on corporate firewalls. It is not a tip for a consumer VPN app on your laptop.
Enterprise gateway ≠ consumer VPN app
A consumer VPN (phone or desktop client) encrypts your traffic to a provider exit and usually changes the public IP sites see. That is the product most people mean when they say “I use a VPN.”
A Check Point Security Gateway with Remote Access or Site-to-Site VPN is different gear:
| Consumer VPN app | Check Point enterprise gateway | |
|---|---|---|
| Who runs it | You (or a consumer brand) | Company / MSP IT |
| Typical job | Hide or relocate exit IP for browsing | Connect offices, staff, or partners into corporate networks |
| These CVEs | Not the target class in the advisories | In scope when VPN features are enabled on affected builds |
| Your action | Keep using or not — unrelated to this CVE pair for most readers | Ask IT if they patched; you cannot “fix” their gateway from FindMyIP |
A shared word in two product names does not establish shared exposure to a vulnerability. Match the advisory to the actual product, enabled features and build. This distinction is not a security endorsement of any consumer VPN service.
Why an IP check cannot answer the patching question
FindMyIP reports the public source address for the request to this website and available network/location data. That result contains no evidence about the software build, patch installation or configuration of a remote Check Point gateway.
A changed exit IP is a separate observation. See what a VPN changes on your visible IP for what that comparison can and cannot establish. Neither a changed address nor an unchanged ISP label is proof that enterprise remote access is secure.
An administrator can establish patch status using the vendor’s supported management and verification procedures. A home user’s web lookup cannot substitute for that information, and switching consumer VPN providers does not patch a company gateway.
If you use company remote access
Some people connect from home into work through a Remote Access VPN that terminates on a Check Point gateway. That is the one personal overlap worth naming.
Practical takeaways only:
- You cannot patch the gateway. Only the people who manage it can apply vendor Hotfix / LivePatch.
- Ask IT once, calmly. “Are we on a fixed build for CVE-2026-85102 / CVE-2026-85103?” is enough. You do not need exploit detail.
- Follow their client updates. Company VPN clients and posture checks are separate from consumer VPN apps.
- Do not “test” the gateway. Probing corporate VPN endpoints is not a normal-user task and is often against policy.
- Keep routing and patch status separate. Company VPNs can use different routing policies. A corporate egress address does not prove that a gateway has received the required fix.
If you never use a work VPN into Check Point gear, you can stop here.
Keep the source and review date with the advice
Security advisories evolve as vendors publish fixed builds, hotfixes and operational guidance. A saved headline or an old screenshot of a version table is not a current patch inventory. The people responsible for the gateway should check their management records and follow the relevant vendor procedure for that deployment.
For a work user, a useful question is whether the organization has checked both CVEs against its deployed Check Point products and applied the required remediation. Follow the administrator’s instructions about availability and client updates. Installing a different personal VPN does not address a vulnerable enterprise appliance.
This article describes the distinction at the review date above. Use the linked vendor advisories for the current affected-build matrix, and CERT-EU for the broader advisory context. It is not a product recommendation or a scan result for your organization.