rootpwn

Threat Intel

Dutch NCSC Warns of Imminent Exploitation of Critical Check Point VPN Flaws

The Dutch NCSC has issued an urgent advisory that two critical vulnerabilities in Check Point VPN—CVE‑2026‑85102 and CVE‑2026‑85103—are likely to be exploited soon. Although no public proof‑of‑concept exists, the agency stresses that the flaws could let attackers execute arbitrary code on Security Gateways and Management Servers, potentially taking full control of affected networks. Check Point released patches on September 9, and the NCSC urges organizations to apply them immediately or use LivePatch. For Site‑to‑Site VPN users, limiting access to trusted IPs is also recommended.

The Dutch Nationaal Cyber Security Centrum (NCSC) has sounded the alarm on two severe Check Point VPN vulnerabilities that could be weaponised in the near term. The flaws, catalogued as CVE‑2026‑85102 and CVE‑2026‑85103, have not yet been publicly exploited, but the NCSC assesses the risk and potential impact as high.

What the Flaws Do

  • CVE‑2026‑85102: Improper validation of certificate data during VPN negotiation, enabling remote code execution on a Security Gateway.
  • CVE‑2026‑85103: Heap overflow in the VPN certificate ASN.1 decoder, also allowing remote code execution on Security Gateways and Management Servers.

Affected Releases

  • R81.20, R82, R82.10
  • R81.10.x, R82.00.x
  • End‑of‑support versions R80 through R80.40, R81, and R81.10
  • Note: R82.20 is not affected.

Patch Availability

  • Check Point LivePatch Take 24 covers R81.20, R82, and R82.10.
  • Hotfix accumulators: Take 44 or later for R82.10, Take 126 or later for R82, and Take 166 or later for R81.20.
  • Spark builds: R82.00.10 Build 2325+ and R81.10.17 Build 4968+ include the fixes.
  • All patches were released on September 9.

How to Protect Your Network

  • Apply the latest security updates or enable LivePatch immediately.
  • Verify that LivePatch protections are active—this is automatic for R82.10, R82, and R81.20 but may not apply to other versions.
  • For Site‑to‑Site VPN deployments, tighten firewall rules to allow traffic only from known, trusted IP addresses.
  • Monitor VPN logs for unusual authentication attempts or certificate anomalies.
“The likelihood of exploitation is high and we expect attempts to surface soon,” the NCSC warned. “Apply the patches now to prevent a potential takeover of your internal network.”

Check Point’s community forums confirm that LivePatch recipients have received the protection as of September 9, and the fixes do not require a server reboot. Administrators should confirm their systems are up to date and adjust VPN access controls accordingly.

Check Point VPN RCE NCSC CVE-2026-85102 CVE-2026-85103 Patch

← All news