Dutch NCSC Warns Attackers Are Poised to Exploit Critical Check Point VPN Flaws
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning that exploitation of two critical flaws in Check Point VPN, tracked as CVE-2026-85102 and CVE-2026-85103, is imminent. Although no public proof-of-concept exploit has surfaced, the agency rates both the likelihood of exploitation and the potential impact as high and is urging organizations to install the available security updates as soon as possible.
The first flaw, CVE-2026-85102, stems from improper validation of certificate data during VPN negotiation and allows a remote attacker to execute arbitrary code on a Security Gateway. The second, CVE-2026-85103, is a heap overflow in the VPN certificate ASN.1 decoder that enables remote code execution on Security Gateways and Security Management Servers. Affected releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, along with end-of-support versions R80 through R80.40, R81, and R81.10, while version R82.20 is not affected.
Check Point addresses both vulnerabilities through LivePatch Take 24 for R81.20, R82, and R82.10, with additional fixes available in the latest Jumbo Hotfix Accumulator releases and Spark builds. The NCSC warns that successful exploitation could let attackers take full control of systems, view or modify confidential data, and disrupt operations, and it advises administrators using the Site-to-Site VPN component to restrict access to trusted IP addresses while patching.