Check Point Fixes Two Critical VPN Flaws That Could Let Hackers In Without a Password

Both bugs score 9.8 out of 10 and affect the firewall gear that guards corporate networks.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal editorial shot of a rack-mounted network security appliance in a dim server room, status LEDs glowing amber, blue fibre cables
Share

Key points

  • Check Point patched two critical flaws in its firewall and management products, each rated 9.8 out of 10 on the industry severity scale.
  • Both bugs sit in the way the products handle VPN certificates, the digital ID cards that prove a remote worker is who they say they are.
  • The company says a remote attacker could run their own code on the device without logging in, but only "under specific conditions" it has not spelled out.
  • One flaw hits Security Gateways, the firewall boxes sold to businesses; the other hits both the gateways and the Security Management Server that controls them.
  • No active exploitation has been reported, but customers are told to install the fixes now.

Check Point, one of the largest firewall makers in the world, has quietly pushed out fixes for two serious bugs in its VPN software.

A VPN, short for virtual private network, is the encrypted tunnel that lets an employee at a coffee shop reach files sitting on the office network. The firewall on the other end of that tunnel checks a certificate, a small cryptographic file that acts like a staff pass, before letting the connection through.

Both of the newly patched flaws live in exactly that check.

What did Check Point actually fix?

Two vulnerabilities in how its products validate VPN certificates. Each was given a severity score of 9.8 out of 10, which is as close to the top of the scale as bugs get without hitting it.

The first flaw affects Check Point's Security Gateways. Those are the physical or virtual firewall appliances that sit at the edge of a company network and decide what traffic is allowed in.

The second flaw affects both those gateways and the Security Management Server, the central console that administrators use to configure a fleet of firewalls at once. If an attacker took over the management server, they would effectively hold the keys to every firewall it controls.

Check Point says both bugs could let an unauthenticated remote attacker, meaning someone on the internet with no account and no password, run code of their choosing on the device. The catch is that this only works "under specific conditions" that the vendor has declined to describe in public, presumably to slow down anyone trying to build a working exploit.

How bad is this in plain terms?

Bad enough that every Check Point customer should patch this week. A firewall is the front door of a corporate network. A bug that lets a stranger run code on the front door, without so much as a login prompt, is the kind of thing ransomware crews and state-backed groups actively hunt for.

Edge devices like VPN concentrators and firewalls have been a favourite target for the last three years. Similar critical flaws in kit from Ivanti, Fortinet, Cisco and Palo Alto Networks have all been used in real attacks, often within days of disclosure.

There is one piece of good news. Check Point, which first disclosed the issues in an advisory covered by The Hacker News, says it has no evidence anyone is exploiting the flaws yet.

Would multi-factor authentication have helped?

Honestly, no, and that is the uncomfortable part. Multi-factor authentication, the extra code from a phone or hardware key, protects the login step. These bugs skip the login step entirely by abusing the certificate check that happens before a user is ever identified.

This is a pure authentication-layer flaw in the protocol handling, not a stolen-password problem. The only fix is the vendor patch.

What should administrators do now?

Install the Check Point hotfixes on every affected gateway and management server. Then check the logs for unusual VPN certificate errors or unexpected administrator sessions over the past few weeks, in case anyone got in early.

Ordinary end users, the staff who click a VPN icon each morning, do not need to do anything. This one is on the IT team.

© 2026 Threat Vectr