Dutch NCSC warns exploitation of two critical Check Point VPN flaws is imminent
CVE-2026-85102 and CVE-2026-85103 allow remote code execution on Security Gateways; fixes shipped September 9 but no public exploit has surfaced yet.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
The Netherlands' Nationaal Cyber Security Centrum is urging organizations to patch two critical vulnerabilities in Check Point VPN immediately, saying it expects exploitation attempts soon. The flaws are tracked as CVE-2026-85102 and CVE-2026-85103. The agency assesses both the likelihood of exploitation and the potential impact as high, even though no public proof-of-concept exploit has been reported. Check Point VPN lets remote employees reach internal corporate networks over encrypted connections, making the gateways a high-value entry point. CVE-2026-85102 is an improper validation of certificate data during VPN negotiation that a remote attacker could use to execute arbitrary code on a Security Gateway. CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder that could allow remote code execution on both Security Gateways and Security Management Servers. Check Point released fixes on September 9 with two advisories, sk1000117 and sk1000118. Affected releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, plus end-of-support versions R80 through R80.40, R81, and R81.10. For R81.20, R82, and R82.10, the fix is delivered as LivePatch Take 24. Organizations still running end-of-support versions face the added problem of being on releases that no longer receive routine updates. The warning fits a pattern this month of edge and remote-access products drawing rapid attacker attention once advisories appear.