LatestMark Carney meets with ‘Forever Canadian’ campaigners in Banff

Canadian business, markets & economy · Saturday, 12 September 2026

Business

Check Point patches two critical CVEs but legacy firewalls face forced upgrades

Two new critical vulnerabilities (CVE‑2026‑85102, CVE‑2026‑85103) affect Check Point’s Security Gateway, Management Server and Spark Firewall. Patches cover current releases, while out‑of‑support versions must be upgraded or lose security updates.

Check Point hardware firewall appliance (Security Gateway / Security Management Server / Spark Firewall) installed in a data‑center rack

Check Point has released security patches for two critical CVEs – CVE‑2026‑85102 and CVE‑2026‑85103 – that affect its Security Gateway, Security Management Server and Spark Firewall products. While the patches protect the current releases, the company warns that legacy, out‑of‑support versions will not receive further updates, forcing administrators to upgrade to a supported version such as R82.20.

Scope of the vulnerabilities

The vulnerabilities allow unauthenticated code execution during VPN certificate handling. In the first flaw, certificate verification errors can let a remote attacker inject malicious code. The second flaw, an ASN.1‑decoding error in the VPN certificate process, also leads to memory‑corruption‑based code execution. Both flaws are present in the same product families: Check Point Security Gateway, Security Management Server and Spark Firewall.

According to heise Online, the affected versions include current releases – R81.10.x, R82.00.x, R81.20, R82 and R82.10 – and a range of legacy releases that are no longer supported: R80, R80.10, R80.20, R80.30, R80.40, R81 and R81.10.

Patch availability and upgrade imperative

Patches have been issued for all supported versions listed above. The company states that no patches are forthcoming for the out‑of‑support releases, meaning those installations will remain vulnerable unless upgraded. The recommended migration path is to move to the latest supported release, R82.20.

Heise Online also notes that Check Point has not observed any exploitation of these vulnerabilities in the wild, but cautions that the situation could change quickly, urging administrators to apply the patches promptly.

Enterprises running legacy firewalls now face a clear decision: invest in hardware or software upgrades to stay protected, or continue operating with known, unpatched risks. The forced migration is likely to generate incremental revenue for Check Point through upgrade licences, extended support contracts, and possible hardware refreshes.

Given Check Point’s 2025 financial results – US$2.73 billion in revenue, US$1.06 billion in net income, US$7.81 billion in total assets and US$2.88 billion in shareholders’ equity for the fiscal year ended 31 December 2025 – the company already commands a strong balance sheet to support a surge in upgrade activity. The figures come from the company’s Form 20‑F filed on 31 March 2026 with the U.S. SEC.

Analysts will likely watch the uptake of the R82.20 upgrade as an early indicator of how quickly customers move away from legacy platforms. A rapid shift could boost Check Point’s services revenue, while a slower pace may expose a segment of the market to prolonged risk.

Check Point at a glance

Check Point Software Technologies Ltd (ticker: CHKP, Nasdaq) is headquartered in Tel Aviv, Israel, and operates in the computer security software sector. The firm was founded in 1993. The latest filed figures (FY 2025) show:

Check Point FY 2025 financial snapshot (source: SEC Form 20‑F)
MetricValuePeriod
RevenueUS$2,725,400,0002025
Net incomeUS$1,056,900,0002025
Total assetsUS$7,806,400,0002025
Shareholders’ equityUS$2,882,100,0002025
Shares outstanding105,596,0352025

These numbers provide context for the scale of Check Point’s operations as it addresses the newly disclosed security flaws.

Version coverage table

Check Point product versions affected by CVE‑2026‑85102/85103 (source: heise Online)
VersionSupport statusPatch available
R81.10.xSupportedYes
R82.00.xSupportedYes
R81.20SupportedYes
R82SupportedYes
R82.10SupportedYes
R80Out‑of‑supportNo
R80.10Out‑of‑supportNo
R80.20Out‑of‑supportNo
R80.30Out‑of‑supportNo
R80.40Out‑of‑supportNo
R81Out‑of‑supportNo
R81.10Out‑of‑supportNo

Customers still on the out‑of‑support releases must plan for migration to avoid a security gap. The timeline for the patches aligns with the disclosure date, which was reported today by Check Point and covered by heise Online.

What remains unknown

  • The exact timeline for customers to complete upgrades – Check Point has not disclosed a deadline.
  • Potential cost differentials between upgrading software only versus replacing hardware for older appliances.
  • Whether any third‑party security services will offer interim mitigation for legacy installations.

Until Check Point provides further guidance, enterprises should treat the vulnerabilities as high‑risk and prioritize the upgrade path.

In short, the immediate technical fix is available for supported versions, but the broader market impact will be measured by how quickly legacy customers move to the R82.20 release and whether the upgrade drives additional revenue streams for Check Point.

About the author

Raj Patel

Reporting for CityAM Canada on business and the wider Canadian economy.

All work by Raj Patel ›