# 2026-012: Critical Vulnerabilities in Check Point Products

Publisher-attributed story with a reviewed brief or permitted publisher paragraph. The original publisher is responsible for the linked reporting.

- Publisher: CERT-EU
- Category: Vulnerabilities
- Original publication time: 2026-09-10T08:20:06Z
- First observed by NexusTechWire: 2026-10-01T17:27:53Z
- Original source: https://cert.europa.eu/publications/security-advisories/2026-012/
- NexusTechWire record: https://nexustechwire.com/news/news-75307c0003846ae69ae4

## From the publisher

On 9 September 2026, Check Point released emergency security updates addressing two critical vulnerabilities affecting Check Point Security Gateway, Security Management Server, and Spark Firewall deployments configured to use Remote Access VPN or Site-to-Site VPN. Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances. CERT-EU strongly recommends applying the available hotfixes as soon as possible, prioritising internet-facing and perimeter appliances.

Source license: [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/). Publisher excerpt shortened and converted to plain text. Original source license applies.

Read the full original: [CERT-EU](https://cert.europa.eu/publications/security-advisories/2026-012/)

This record does not reproduce the complete article or represent independent confirmation of every source claim.
