Return to Threats

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

thehackernews.com 2026-09-10 AI supply chain Critical

What Happened

Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security

Why It Matters

Report facts: Check Point disclosed and patched two critical (CVSS 9.8) vulnerabilities in how its firewall and management products process VPN certificates, enabling unauthenticated remote code execution under specific, undisclosed conditions. One flaw impacts Security Gateways firewall appliances, while the other impacts both those gateways and related management products. RealGround analysis: Although not AI-specific, these issues highlight systemic risks in the software and network security supply chain that can indirectly compromise AI infrastructure and data if such VPN and gateway products are part of an organization's AI environment. Organizations should treat this as a trigger to review third‑party security product dependencies, update SBOMs, and validate patch management and remote access controls across systems that host or connect to AI workloads.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html

Talk to AI CISO