Check Point has patched two critical vulnerabilities, both rated 9.8 out of 10, in the VPN component of its firewalls — including the Spark Firewall, a model Check Point sells specifically to small and medium businesses. If your office uses a Check Point device for site-to-site VPN between locations or remote-access VPN for staff working from home, the short version is: apply the hotfix this week, and don't wait for it to show up as "actively exploited" first.
What actually happened
Check Point's own engineers found the two flaws during internal testing and disclosed them on 7 September 2026, updating the advisory on 9 September. Fixes went out the same day via Check Point's Live Patch mechanism and updated Jumbo Hotfix packages, covering the R82.10, R82 and R81.20 software versions.
The two bugs are:
- CVE-2026-85102 — the firewall doesn't properly validate a certificate during VPN negotiation, letting an attacker impersonate a trusted party without a login of any kind. Affects Security Gateway and Spark Firewall.
- CVE-2026-85103 — a heap overflow in how the firewall decodes certificate data, which can be triggered the same way. Affects Security Gateway, the Security Management Server, and Spark Firewall.
Both are "unauthenticated" flaws, meaning an attacker doesn't need a password, a phished login or any prior access to your network — just the ability to send traffic to the device's VPN interface, which by design is usually reachable from the public internet. Successfully exploiting either one can hand an attacker remote code execution on the firewall itself: the box that's meant to be your business's front door lock.
There's an important difference from most of the CVEs that make headlines: Check Point found these itself, before criminals did, and there's no confirmed exploitation in the wild at the time of writing. That's the good version of this story — you get to patch a critical hole before it's used against you, rather than reading about it after the fact. That window won't stay open long. Once an advisory like this is public, security researchers and criminal groups alike start reverse-engineering the fix to work out exactly what it protects against, and a working exploit usually follows within days to weeks.
Why the "Spark" name matters
A lot of the firewall CVEs Perth businesses hear about affect large enterprise gear most small offices don't run — Cisco's Firewall Management Center, Citrix NetScaler, big Fortinet appliances. Spark Firewall is different: Check Point built and markets it as the entry-level option for smaller businesses running one office or a handful of sites, often installed once and left to quietly do its job for years. That's exactly the kind of device that's easy to forget needs patching, because nobody's logging into its admin console day to day.
If a managed IT provider set up your internet connection, network security or site-to-site VPN between offices, there's a reasonable chance a Check Point device — Spark or a larger Security Gateway — is what's doing the work.
What to check this week
- Identify what firewall/VPN gateway your business actually runs. If you don't know off the top of your head, that's a normal thing not to know — it's exactly the kind of detail your IT provider should have on file. Ask them directly: "Do we run Check Point, and have the September 2026 VPN hotfixes (CVE-2026-85102 / CVE-2026-85103) been applied?"
- If you manage the device yourself, check the software version against R82.10, R82 or R81.20 and confirm the relevant hotfix or Jumbo Hotfix has been installed — Check Point's advisory and Live Patch panel will confirm current status.
- Prioritise internet-facing gear first. Anything with a public IP address handling VPN traffic is the priority; internal-only management servers are lower risk but should still be patched.
- Don't disable VPN as a stopgap unless a provider specifically tells you to — for most Perth businesses, the VPN is how remote staff, other offices, or a managed IT provider's monitoring tools reach you, so switching it off usually creates a different problem.
The pattern worth remembering
This is at least the third time in September alone that a VPN or firewall vendor has needed an emergency patch for a flaw that let an attacker in without a password — Windows' own built-in VPN, Cisco and Citrix's remote-access gear, and now Check Point's. None of that means any particular brand is worse than another; it means the device sitting at the edge of your network, whichever brand it is, is a permanent target, and "we set it up once and it's been fine" isn't a security strategy on its own.
A managed firewall service exists precisely to close this gap — someone whose job is to know a hotfix landed on 9 September and confirm it's applied on 10 September, rather than finding out from a client after something's gone wrong. If you're not sure who's watching your firewall's patch status, that's worth an actual conversation this week, not a note for later.
For a broader look at protecting the rest of your network alongside the firewall itself, our IT security solutions page covers what a properly layered setup looks like. And if this is the second or third "patch your VPN now" story you've seen this month, you're not imagining it — we covered the Windows VPN flaw under active attack in August and Cisco, Citrix and Fortinet firewall issues just last week.
If your business runs a Check Point firewall, or you simply don't know what's protecting your network's front door, get in touch with Computer Mechanics — Perth IT specialists since 1997 — and we'll check it for you.



