Dutch Cyber Agency Warns of Critical Check Point VPN Vulnerabilities Exploitable Soon

www.news4hackers.com-dutch-cyber-agency-warns-of-critical-check-point-vpn-vulnerabilities-exploitable-soon-dutch-cyber-agency-warns-of-critical-check-point-vpn-vulnerabilities-exploitable-soon

Dutch national cybersecurity officials have issued an urgent alert regarding two critical vulnerabilities in Check Point’s VPN systems, which could be exploited imminently.

Urgent Alert

The flaws, designated as CVE-2026-85102 and CVE-2026-85103, both carry a severity rating of 9.8 out of 10. These vulnerabilities affect multiple Check Point products, including Security Gateway, management servers, and Spark Firewall solutions. The Dutch National Cyber Security Centre (NCSC) has emphasized that exploitation attempts are anticipated shortly, urging organizations to implement available patches without delay.

Critical Vulnerabilities

Check Point has not confirmed active exploitation of either flaw in real-world scenarios. The most critical aspect of these vulnerabilities is that they allow attackers to bypass authentication requirements entirely.

How the Vulnerabilities Work

CVE-2026-85102 involves a flaw in how Check Point Security Gateway validates certificate data during VPN connections. This vulnerability could enable remote adversaries to circumvent security protocols and execute malicious code on the gateway. CVE-2026-85103 stems from a heap overflow issue in the handling of VPN certificate data, which similarly permits remote code execution. Both flaws can be exploited without requiring user credentials, making them particularly dangerous.

Affected Products

A virtual private network (VPN) establishes an encrypted link between a user or network and an organization’s internal systems. Security gateways manage these connections, acting as the first line of defense against external threats. Remote code execution (RCE) vulnerabilities are among the most severe due to their potential to grant attackers full control over affected devices.

Recommendations

If exploited, these flaws could allow adversaries to compromise network security appliances, which often have privileged access to internal resources. The affected products include various versions of Check Point Security Gateway across R80, R81, and R82 release lines, as well as specific Spark Firewall models. CVE-2026-85103 also impacts Security Management Server deployments.

Conclusion

The vulnerabilities become relevant when systems are configured for Remote Access VPN or Site-to-Site VPN. CERT-EU has advised organizations to prioritize patching internet-facing and perimeter systems. The Dutch NCSC has highlighted the heightened risk associated with public disclosure of critical vulnerabilities. Once technical details are available, attackers can reverse-engineer patched and unpatched software to identify exploit methods. This creates a narrow window for organizations to apply mitigations before widespread scanning occurs.

Check Point has released a Jumbo Hotfix to address the flaws and recommends enabling Live Patch for automatic protection. For systems unable to apply updates immediately, the company has outlined temporary measures, such as restricting UDP ports 500 and 4500 to trusted IP addresses for Site-to-Site VPN users. Attackers increasingly target VPN gateways and firewalls due to their strategic role in network defense. Compromising these devices provides a direct entry point into an organization’s infrastructure. Once inside, adversaries may steal credentials, deploy ransomware, or establish persistent access.

Organizations utilizing Check Point’s VPN and security infrastructure should immediately identify affected systems, apply the latest patches, and implement network restrictions where possible. The Dutch NCSC’s warning underscores a broader trend in cybersecurity: perimeter defenses, designed to block threats, can become the weakest link if compromised. With these vulnerabilities now publicly disclosed, the period between patch release and mass exploitation may determine the scale of potential breaches.


Blog Image

About Author

en_USEnglish