9 min read

Check Point VPN Flaws: Swiss Perimeter Risk 2026

CERT-EU has highlighted two CVSS 9.8 vulnerabilities in Check Point products. Swiss organisations should treat exposed VPN gateways as an emergency asset-management and evidence problem.

CERT-EU’s September advisory on CVE-2026-85102 and CVE-2026-85103 puts Check Point perimeter appliances on the priority list for European defenders. Both vulnerabilities are reported with a CVSS score of 9.8 and the potential for unauthenticated code execution. For Swiss banks, healthcare providers, manufacturers and public entities, the issue is not simply whether a patch exists. It is whether every internet-facing gateway is known, protected, verified and covered by an incident record.

VPN infrastructure is a high-value control plane. It sits between external users and internal services, handles identity and encryption, and often has privileged access to management networks. A compromise can therefore bypass controls that would otherwise slow an attacker inside the data centre. Swiss organisations should respond as though the appliance itself may be the initial foothold, while preserving enough evidence to determine whether access already occurred.

Why perimeter exposure changes the decision

A vulnerability score does not tell an organisation whether it is exposed. That answer comes from inventory, version data and network telemetry. Security teams should identify every Check Point gateway, management server, cluster member, cloud instance and delegated tenant, including assets operated by a managed service provider. Old appliances and disaster-recovery sites are common blind spots because they are documented in contracts rather than in the central asset register.

Exposure should be assessed from the internet, not only from internal scanning. Confirm which interfaces accept connections, which administrative services are reachable, and whether remote access is restricted by geography, identity or a separate access broker. A gateway that is not in the main production inventory can still be the route into a sensitive environment. Record the public address, product family, software build, owner and business dependency for every instance.

Do not infer safety from an absence of alerts. Exploitation of a perimeter device may leave limited endpoint evidence, especially if the attacker uses valid remote-access paths or alters logging. The response must combine appliance logs, management-plane events, authentication records, VPN session history and downstream telemetry.

◆ Key Takeaway

For a critical VPN vulnerability, “patched” is not the end state. Swiss teams need a verified inventory, a controlled mitigation, evidence of the change and a documented decision about possible prior compromise.

Containment before the maintenance window

Patch according to the vendor’s current guidance and confirm that the update applies to the exact product and release branch in use. If a maintenance window is not immediately available, reduce exposure without creating a false sense of security. Restrict management access, disable unused remote-access services, enforce stronger authentication where supported and place vulnerable gateways behind an additional filtering layer. These measures are temporary controls, not substitutes for remediation.

Plan for failure. A perimeter change can interrupt clinical access, trading connectivity, manufacturing lines or emergency administration. The change record should identify the business owner, rollback path, out-of-band management method and validation checks. For clustered systems, define the order of operations and verify that a supposedly passive member is not still reachable through a separate address.

Managed service arrangements need explicit coordination. Ask the provider for the affected asset list, patch timestamps, validation evidence and any signs of suspicious access. Contractual responsibility does not remove the Swiss organisation’s need to understand its own exposure, particularly where FINMA, ISA or customer commitments require evidence of operational resilience.

Investigate the possibility of access

Investigation should begin before logs rotate. Preserve gateway and management logs, authentication events, configuration history, administrator activity, certificate changes and unusual VPN sessions. Export copies to a trusted location and record the time zone and collection method. If the appliance supports forensic snapshots or vendor diagnostic bundles, follow the supplier’s instructions so that evidence is not overwritten by an improvised reset.

Look for unexpected administrator creation, policy changes, new certificates, altered logging, unfamiliar source addresses and sessions at unusual times. Correlate those events with identity-provider records, endpoint alerts and access to high-value applications. Pay particular attention to accounts that authenticated through the gateway shortly before an unexplained internal change.

If compromise cannot be ruled out, rotate credentials and certificates from a clean administrative path. Review downstream trust relationships rather than limiting the response to the appliance. A gateway may have exposed privileged accounts even when no malicious payload is visible. Legal, privacy and communications teams should be involved early if customer data, regulated services or third-party environments may have been reached.

Actions for Swiss perimeter owners

  • Reconcile the internet-facing asset inventory against DNS, certificate, firewall and provider records.
  • Identify every Check Point product, exact build, owner, support status and business dependency.
  • Apply the vendor fix or documented compensating control, then verify the result from an external vantage point.
  • Preserve gateway, management, identity and VPN logs before retention windows expire.
  • Hunt for administrator changes, certificate updates, unusual sessions and altered logging around the exposure period.
  • Rotate credentials and trust material through a clean path when compromise cannot be excluded.
  • Record the decision, evidence, residual risk and notification assessment for FINMA, ISA, customers and insurers.

The immediate objective is to remove vulnerable exposure, but the strategic lesson is broader. VPN gateways deserve the same ownership discipline as core identity systems because they translate an external connection into internal trust. Swiss organisations that can prove where their perimeters are, how they were remediated and what was investigated will be better positioned for the next critical advisory, regardless of vendor.