Dutch NCSC Warns of Likely Exploitation of Critical Check Point VPN Vulnerabilities
The Netherlands’ National Cyber Security Centre (NCSC) has warned organizations to rapidly address two critical vulnerabilities affecting Check Point VPN products, saying it expects exploitation attem...
The Netherlands’ National Cyber Security Centre (NCSC) has warned organizations to rapidly address two critical vulnerabilities affecting Check Point VPN products, saying it expects exploitation attempts in the near term.
The flaws, tracked as CVE-2026-85102 and CVE-2026-85103, were patched by Check Point on September 9. While the NCSC said it was not aware of a publicly available proof-of-concept exploit, it assessed both the likelihood and potential impact of attacks as high.
Remote code execution risk
CVE-2026-85102 involves insufficient validation of certificate data during VPN negotiation. According to Check Point, a remote attacker could potentially use the issue to run arbitrary code on a Security Gateway.
The second flaw, CVE-2026-85103, is a heap overflow in the VPN certificate ASN.1 decoder. Successful exploitation could enable remote code execution on Check Point Security Gateways and Security Management Servers.
The NCSC said compromise of a vulnerable device could allow attackers to gain extensive control over affected systems, access or alter sensitive information, and interrupt business operations. VPN gateways are often internet-facing and provide a path into internal corporate networks, making them a high-priority target for threat actors.
Updates and mitigations
Affected products include several R81 and R82 releases, as well as older end-of-support versions. Check Point said the issues are addressed in LivePatch Take 24 for R81.20, R82 and R82.10. Fixes are also available through updated Jumbo Hotfix Accumulators and supported Spark builds.
- R82.10 Jumbo Hotfix Accumulator Take 44 or later
- R82 Jumbo Hotfix Accumulator Take 126 or later
- R81.20 Jumbo Hotfix Accumulator Take 166 or later
- Spark R82.00.10 Build 2325 or later
- Spark R81.10.17 Build 4968 or later
Check Point VPN R82.20 is not affected, according to the vendor. Organizations using Site-to-Site VPN deployments should also restrict VPN rules to known and trusted IP addresses where possible. Administrators using Check Point LivePatch should verify that the automatic protections have been applied, as coverage depends on the product version and configuration.
