Check Point's two 9.8s are in the code that reads the certificate before deciding whether to trust it
2026-09-11Security
CVE-2026-85102 and CVE-2026-85103 both sit in VPN certificate handling on Check Point gateways and management servers, and both run before authentication. Check Point found them itself and has seen no exploitation. The end-of-support releases it lists as affected get no fix at all.