Skip to finding
important · Edge — Check Point

Crafted VPN certificate data may give an unauthenticated peer code execution on Check Point gateways and management servers.

Affects

Check Point Security Gateways, Security Management Servers and Spark appliances processing Site-to-Site or Remote Access VPN traffic.

The pre-authentication paths involve improper certificate validation and a heap overflow in VPN certificate ASN.1 decoding.

Detail and 3 sources

No public exploit or researcher demonstration establishes the terminal execution context, so the code-execution result remains provisional.

Check Point has shipped fixes for both paths.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 12, 2026