Dutch NCSC Warns of Critical Check Point VPN Flaws Exploitation Risk
Urgent alert from the Dutch NCSC highlights critical Check Point VPN vulnerabilities that could be exploited imminently.
Urgent Alert from Dutch NCSC
The Dutch Nationaal Cyber Security Centrum (NCSC) has issued an urgent alert regarding the imminent exploitation of two critical vulnerabilities affecting Check Point VPN products. These flaws, designated CVE-2026-85102 and CVE-2026-85103, pose significant risks to organizations utilizing the platform for secure remote access. While no public proof-of-concept exploits have been disclosed, the NCSC emphasizes the high likelihood of active attacks and advises immediate remediation.
Vulnerabilities Overview
CVE-2026-85102 involves improper validation of certificate data during VPN authentication, allowing a remote attacker to execute arbitrary code on Security Gateways. CVE-2026-85103 stems from a heap overflow in the VPN certificate ASN.1 decoder, which could also lead to remote code execution on Security Gateways and Security Management Servers.
Affected Software Versions
The affected software versions include R81.20, R82, R82.10, R81.10.x, R82.00.x, and end-of-support (EoS) releases R80 through R80.40, R81, and R81.10. Notably, Check Point VPN version R82.20 is not impacted by either vulnerability.
Patches and Mitigations
Check Point has provided patches via LivePatch Take 24 for R81.20, R82, and R82.10. Additional fixes are included in specific hotfix accumulators and build versions, such as R82.10 Jumbo Hotfix Accumulator Take 44 or later, R82 Jumbo Hotfix Accumulator Take 126 or later, and R81.20 Jumbo Hotfix Accumulator Take 166 or later. Spark versions R82.00.10 Build 2325 or later and R81.10.17 Build 4968 or later also incorporate the necessary updates.
Recommendations
The NCSC highlights that exploitation of these flaws could enable attackers to gain full system control, access or alter sensitive data, and disrupt critical operations. System administrators are urged to apply the available updates promptly. For users relying on the Site-to-Site VPN component, the agency recommends adjusting VPN rules to restrict access to verified IP addresses. Check Point users utilizing LivePatch (CPLP) were automatically protected against the vulnerabilities as of September 9, according to community forum discussions.
Conclusion
The NCSC’s warning underscores the urgency of addressing these vulnerabilities, as threat actors are likely to target unpatched systems in the near future. Enterprises must prioritize remediation to mitigate the risk of compromise and maintain operational resilience.
