<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔴 Critical: Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE]]></title><description><![CDATA[<p dir="auto"><strong>Check Point</strong> has patched two critical vulnerabilities in how its firewall and management products handle <strong>VPN certificates</strong>. Both flaws carry a <strong>CVSS score of 9.8</strong>, and according to the company, they could allow an unauthenticated remote attacker to execute code — though only "under specific conditions" that Check Point has not disclosed.</p>
<p dir="auto">The two issues are distinct in scope:</p>
<ul>
<li>One flaw affects <strong>Check Point Security Gateways</strong>, the company's firewall appliances.</li>
<li>The second affects those same gateways as well as the <strong>Security Management</strong> side of the product line.</li>
</ul>
<p dir="auto">The article does not provide specific CVE identifiers for either vulnerability, so no advisory numbers are cited here. Administrators should refer to Check Point's official guidance for exact patch details and affected builds.</p>
<p dir="auto">Because exploitation requires conditions Check Point has chosen not to describe, the practical risk is difficult to assess from the public disclosure alone. Even so, a <strong>9.8</strong> rating and unauthenticated RCE potential make prompt patching the sensible default for anyone running the affected gateway or management components.</p>
<p dir="auto">Mitigation steps:</p>
<ul>
<li>Apply the vendor's patches for <strong>Security Gateways</strong> and <strong>Security Management</strong> as soon as possible.</li>
<li>Verify which of your deployments fall into the affected product sets before assuming you are in the clear.</li>
<li>Monitor vendor advisories for updated technical detail, since the triggering conditions remain undisclosed.</li>
</ul>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Are your Check Point gateways or management servers already patched against these two flaws?</p>
]]></description><link>https://xploitlk.com/topic/294/critical-check-point-discloses-two-9.8-rated-vpn-certificate-flaws-enabling-unauthenticated-rce</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 05:34:07 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/294.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 11 Sep 2026 06:30:24 GMT</pubDate><ttl>60</ttl></channel></rss>