Dutch NCSC Warns Imminent Exploitation of Critical Check Point VPN Flaws

Agency urges immediate patching of CVE-2026-85102 and CVE-2026-85103; fixes available since September 9

edit
By LineZotpaper
Published
Read Time2 min
The Dutch National Cyber Security Centre (NCSC) has warned that exploitation of two critical vulnerabilities in Check Point VPN products is imminent, urging organisations to install security updates as soon as possible. The flaws, tracked as CVE-2026-85102 and CVE-2026-85103, could allow remote code execution on Security Gateways and Management Servers.

The NCSC assesses both the likelihood of exploitation and the potential impact as high, stating it "expects exploitation attempts to occur soon." Although no public proof-of-concept exploit has been reported to date, the agency warns that an attacker could take full control of a system, view or modify confidential data, and disrupt operations.

Check Point VPN is an enterprise solution enabling remote employees to securely connect to internal networks via encrypted connections. The flaws affect multiple releases, including R81.20, R82, R82.10, R81.10.x, and R82.00.x, as well as end-of-support versions R80 through R80.40, R81, and R81.10. Version R82.20 is not affected.

CVE-2026-85102 involves improper validation of certificate data during VPN negotiation, while CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder. Both can be exploited by a remote attacker.

Check Point issued fixes on September 9 via security advisories sk1000117 and sk1000118. Patches are included in LivePatch Take 24 for R81.20, R82, and R82.10, as well as in specific Jumbo Hotfix Accumulator builds. Users of Check Point Live Patch (CPLP) should have received automatic protections since September 9, applicable without a server reboot, though coverage is limited to supported versions.

The NCSC also advises administrators using the Site-to-Site VPN component to modify VPN rules to restrict access to trusted IP addresses as an additional mitigation step.

§

Analysis

Why This Matters

  • These vulnerabilities affect a widely used enterprise VPN solution, putting countless organisations at risk of network compromise.
  • The Dutch NCSC's rare public alert signals a credible threat, likely based on intelligence or active scanning activity.
  • Successful exploitation could grant attackers persistent access to internal networks, enabling data theft, ransomware deployment, or lateral movement.

Background

Check Point is a major cybersecurity vendor whose VPN gateways are deployed in enterprise environments worldwide. The two flaws reside in certificate handling during VPN negotiation, a common attack surface for remote access systems. Historical patterns show that critical-rated VPN vulnerabilities often trigger mass exploitation within days of patch availability, especially once reverse-engineered from binary diffs.

Key Perspectives

Dutch NCSC: The agency assesses exploitation as imminent and urges immediate patching, reflecting high confidence in incoming attacks. Check Point: The vendor released fixes on September 9 and has communicated through security advisories and community forums, advising CPLP users to verify automatic mitigation. Security community: No PoC has been published yet, but the detailed advisory may enable reverse engineering, prompting a race between patching and exploit development.

What to Watch

  • Appearance of proof-of-concept code or active exploitation reports in the coming days.
  • Whether attackers target end-of-support versions (R80–R81.10) that will not receive official patches.
  • Updates from Check Point regarding any observed exploitation or additional mitigations.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.