Skip to content
Tech News
← Back to articles

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

read original get YubiKey 5 NFC Security Key → more articles
Why This Matters

Enterprise VPN gateways are prime targets because they sit at the network edge and grant access to internal systems, so two critical pre-patch RCE flaws in Check Point VPN are a serious risk for any organization running affected releases. The Dutch NCSC's warning that exploitation is imminent, despite no public PoC, signals that defenders have a narrow window to patch before attackers move.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — When VPN gateways are under threat, hardware-backed authentication is a smart extra layer for remote access and admin accounts. The YubiKey 5 NFC plugs into USB-A or taps via NFC and works with a wide range of enterprise and consumer services, making phishing-resistant logins easy for every employee.

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.

Although no public proof-of-concept (PoC) exploit has been reported, the agency is urging organizations to install the security updates addressing the two issues as soon as possible.

“The NCSC assesses the likelihood of exploitation and the potential impact as high and expects exploitation attempts to occur soon,” the NCSC warns.

Check Point VPN is an enterprise solution that allows remote employees to securely connect to their company's internal network via encrypted connections.

On September 9, Check Point issued fixes for the flaws along with separate security advisories describing them: sk1000117 and sk1000118.

CVE-2026-85102 is an improper validation of certificate data during VPN negotiation that a remote attacker could exploit to execute arbitrary code on a Security Gateway.

CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder that could allow remote code execution on Security Gateways and Security Management Servers.

Affected releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, along with the end-of-support (EoS) versions R80 through R80.40, R81, and R81.10.

Both flaws are fixed by Check Point LivePatch Take 24 for R81.20, R82, and R82.10, while fixes are also included in the following versions:

R82.10 Jumbo Hotfix Accumulator Take 44 or later

... continue reading