The NCSC assesses both the likelihood of exploitation and the potential impact as high, stating it "expects exploitation attempts to occur soon." Although no public proof-of-concept exploit has been reported to date, the agency warns that an attacker could take full control of a system, view or modify confidential data, and disrupt operations.
Check Point VPN is an enterprise solution enabling remote employees to securely connect to internal networks via encrypted connections. The flaws affect multiple releases, including R81.20, R82, R82.10, R81.10.x, and R82.00.x, as well as end-of-support versions R80 through R80.40, R81, and R81.10. Version R82.20 is not affected.
CVE-2026-85102 involves improper validation of certificate data during VPN negotiation, while CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder. Both can be exploited by a remote attacker.
Check Point issued fixes on September 9 via security advisories sk1000117 and sk1000118. Patches are included in LivePatch Take 24 for R81.20, R82, and R82.10, as well as in specific Jumbo Hotfix Accumulator builds. Users of Check Point Live Patch (CPLP) should have received automatic protections since September 9, applicable without a server reboot, though coverage is limited to supported versions.
The NCSC also advises administrators using the Site-to-Site VPN component to modify VPN rules to restrict access to trusted IP addresses as an additional mitigation step.