Home / Sep 11, 2026 / Story
0
#5 The Hacker News general September 10, 2026 at 11:45 UTC

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

By [email protected] (The Hacker News)

AI Summary

Check Point disclosed two critical vulnerabilities rated CVSS 9.8 in its Security Gateway firewall appliances and Security Management products, both related to VPN certificate handling and enabling unauthenticated remote code execution under unspecified 'specific conditions.' The vulnerabilities affect widely deployed Check Point perimeter security infrastructure, and the vendor's refusal to detail the triggering conditions limits defenders' ability to assess exposure. Organizations using Check Point Security Gateways should apply the available patches immediately given the RCE severity and unauthenticated attack vector.

Relevance score: 84.0/100

# More from September 11