CYBER DESK · HONG KONG · WEEKLY

Check Point's Own Bug, Everyone Else's Deadline

Check Point patched two critical VPN flaws before anyone exploited them, but the manual hotfix APAC banks must run is slower than attackers have historically needed to catch up.
KT

The Vendor Found It First

Check Point disclosed two vulnerabilities in its Quantum Security Gateway and Security Management Server software on September 9, and said its own research team found both before anyone else did. CVE-2026-85102 is a certificate trust validation flaw that lets an unauthenticated party trigger remote code execution during VPN negotiation. CVE-2026-85103 is a heap overflow in the same VPN certificate handling code, the ASN.1 decoder that parses the certificate's binary structure, and it reaches both the gateway and the management server behind it. Both score 9.8 out of 10 on the industry's severity scale. Check Point's own account is unusually clean: no evidence of exploitation, no public proof of concept, a fix already shipped via LivePatch and as Jumbo Hotfix Accumulator builds across the affected version lines. Four days later the Dutch Nationaal Cyber Security Centrum rated both the likelihood and the impact of exploitation 'high' and said attempts should be expected soon, a phrase that in these advisories functions less as a forecast than as a countdown timer. Nobody in that sentence has seen an attack yet. The Dutch agency is reading the vulnerability class, not a log file, and that class has burned Ivanti and Fortinet customers on a schedule measured in weeks.

One Console, Every Gateway

The dangerous half of this disclosure is not the gateway. It's the Security Management Server, the console that pushes security policy to every Quantum gateway an organization runs, and CVE-2026-85103 reaches it through the same certificate decoding path. Burns & McDonnell's technical analysis, published under its 1898 Advisories brand, put the consequence plainly: a single compromised management server exposes not one appliance but the policy for the entire managed fleet. That is not a hypothetical this week: perimeter VPN and firewall management consoles have repeatedly turned single flaws into estate-wide compromises once attackers get past the same trust and authentication logic that guards everything else on the device. Check Point's version has no confirmed exploitation yet. The historical pattern on this class of device is that confirmation, when it comes, comes fast.

The Hotfix Has To Queue

LivePatch applies for institutions that already run it, which is the automatic route. Everyone else installs the Jumbo Hotfix Accumulator by hand, through whatever change control governs their gateway estate, and that is where the clock problem lives. A bank's technology risk committee wants a test window, a rollback plan, a maintenance slot that doesn't collide with month end settlement. None of that is unreasonable. All of it takes days the historical record has not been generous with: Ivanti's and Fortinet's edge appliance flaws were both reverse-engineered from the vendor patch and weaponized within one to three weeks of disclosure, not months. A bank running a multi-year change-control cycle inherited long before anyone had heard of a Jumbo Hotfix is not being negligent. It is running the same cycle that cleared every other patch on schedule, against a device class that no longer waits for the cycle to finish. Regulators across the region expect banks to patch critical systems within a defined window once active exploitation is confirmed. Nothing is confirmed yet. That is exactly the gap the Dutch warning is asking banks to close before it opens.

As of today, nobody has weaponized CVE-2026-85102 or CVE-2026-85103. The entire state of play is a vendor that found its own bug, a regulator that doesn't expect it to stay that way, and a patch that has to clear change control before either one is proven right. The control that resolves this is not a firewall rule. It is enabling LivePatch before the next disclosure lands, so the fix that ships automatically doesn't have to wait for a meeting.

Sources

PREVIOUS COLUMNS, CYBER INTEL DESK
The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.