Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk

Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk

Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk

Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk

Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk

Pierluigi Paganini
September 14, 2026

Two critical Check Point VPN flaws score 9.8 and could enable remote code execution. Patch now and restrict VPN access before exploitation begins.

The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN products, both rated CVSS score of 9.8, could soon be actively exploited. If you use Check Point VPN, you should patch it immediately.

CVE‑2026‑85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks and run their own code on the gateway. CVE‑2026‑85103 is a heap overflow in the certificate ASN.1 decoder that also leads to remote code execution on Security Gateways and Security Management Servers.

Both vulnerabilities can be triggered by external attackers, and while no public proof‑of‑concept has surfaced yet, the NCSC explicitly rates the likelihood of exploitation and the potential damage as high.

“There are 2 critical vulnerabilities in Check Point VPN products with the attributes CVE-2026-85102 and CVE-2026-85103. These are 2 serious vulnerabilities with a CVSS score of 9.8.” reads the alert. “The NCSC assesses the likelihood of exploitation and potential damage as high and expects that attempts at exploitation will occur soon; therefore, the advice is to install the updates as soon as possible.”

An attacker can take over the system, read or change confidential data, and disrupt operations. In practice, that means your VPN appliance stops being a secure entry point and starts being a beachhead inside your network.

Check Point addressed the flaws on September 9 with the release of the advisories sk1000117 and sk1000118. The affected releases span R81.20, R82, R82.10, R81.10.x and R82.00.x, plus end‑of‑support versions from R80 through R81.10. R82.20 is not affected.

For supported versions, Check Point provides fixes through LivePatch Take 24 or specific Jumbo Hotfix updates, depending on the version you use.

If you use LivePatch with R81.20, R82 or R82.10, your system may already be protected without a reboot. However, you should check your setup to make sure. LivePatch does not cover every version or configuration, so don’t assume you are protected.

The NCSC’s advice is straightforward: install the updates as soon as possible. For organizations using Site‑to‑Site VPN, it also recommends tightening the ruleset: disable implied rules and restrict VPN access to specific, trusted IP addresses instead of leaving it wide open. If you’re not sure whether you’re running a vulnerable version, talk to your IT provider now, not after the first IOC shows up in your logs.

“The NCSC advises installing these updates as soon as possible. For organizations using Site-to-Site VPN, it is recommended to adjust certain VPN rules, such as disabling implied rules and restricting VPN access to specific IP addresses.” concludes the alert. “Contact your IT service provider if you are unsure whether you are using a vulnerable version. If necessary, ask for assistance in implementing the recommended measures.”

This isn’t a “schedule a change window next month” situation. It’s a “verify, patch, restrict, and move on before someone else decides your VPN is their new favorite initial access broker” kind of week.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Check Point)



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.