HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Check Point Discloses Two 9.8‑Rated VPN Certificate Flaws Enabling Unauthenticated RCE

Check Point announced two CVSS 9.8 vulnerabilities in its firewall and management VPN certificate handling that permit unauthenticated remote code execution. Organizations must patch quickly and capture remediation evidence to satisfy vulnerability‑management controls across frameworks such as NIST CSF 2.0.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

Check Point Discloses Two 9.8‑Rated VPN Certificate Flaws Enabling Unauthenticated RCE

What Happened — Check Point disclosed two critical vulnerabilities in its Security Gateway and Management‑Server VPN certificate handling. Both flaws receive a CVSS 9.8 rating and could allow an unauthenticated remote attacker to execute arbitrary code when specific, undisclosed conditions are met.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous vulnerability monitoring and rapid patch deployment to keep control‑objective evidence up‑to‑date.
  • Without documented remediation, organizations struggle to prove compliance with the “Vulnerability Management” control that underpins many frameworks (e.g., NIST CSF 2.0).
  • Verisq’s Control Mapping capability can automatically capture patch‑status evidence, turning a reactive fix into a defensible audit artifact.

Who Is Affected – Enterprises, MSPs, and cloud‑infrastructure teams that run Check Point Security Gateways or Management Servers in production environments.

Recommended Actions

  1. Identify any deployed Check Point appliances that match the affected versions.
  2. Apply the vendor‑supplied patches immediately.
  3. Update your vulnerability‑management workflow to ingest patch‑deployment logs as continuous evidence.
  4. Map the remediation activity to the “Vulnerability Management” control objective for audit readiness.

Source: The Hacker News

Technical Notes – The attack vector exploits certificate‑validation logic in the VPN subsystem; exploitation requires crafted certificate data but no prior authentication. CVE identifiers have been assigned (CVE‑2026‑XXXX, CVE‑2026‑YYYY) with a CVSS base score of 9.8. No public exploits are known at the time of disclosure.

Source: same as above

📰 Original Source
https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →