SECURITY·중요도 9·2026. 09. 10.·The Hacker News
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
── KO ──────────────────
Check Point의 VPN 인증서 취약점이 발견되어 원격 코드를 실행할 수 있는 위험이 존재합니다.
Check Point는 VPN 인증서를 처리하는 과정에서 발견된 두 가지 치명적인 취약점을 수정했습니다. 이 결함들은 인증되지 않은 원격 공격자가 코드를 실행할 수 있게 할 수 있지만, 특정 조건에서만 가능하다고 회사는 밝혔습니다. 첫 번째 취약점은 Check Point의 Security Gateways에 영향을 미치며, 두 번째는 이 게이트웨이와 Security Management에 모두 영향을 줍니다.
── EN ──────────────────
Check Point disclosed VPN certificate flaws allowing unauthenticated remote code execution.
Check Point has patched two critical vulnerabilities related to how its products handle VPN certificates. Both flaws could enable unauthenticated remote attackers to execute code, but only under unspecified conditions. One flaw affects Check Point's Security Gateways, while the other impacts these gateways and the Security Management products.