The Dutch National Cyber Security Centre (NCSC) has issued an urgent warning regarding two critical vulnerabilities in Check Point VPN. Organizations are urged to patch immediately to prevent full system takeovers.
- Two critical flaws, CVE-2026-85102 and CVE-2026-85103, have been identified in Check Point VPN.
- Attackers could achieve Remote Code Execution (RCE) and gain total system control.
- Immediate installation of security updates is mandatory for affected versions.
The Dutch Nationaal Cyber Security Centrum (NCSC) has sounded the alarm over two critical vulnerabilities within Check Point VPN, tracked as CVE-2026-85102 and CVE-2026-85103. While no public proof-of-concept (PoC) exploit has surfaced yet, the agency warns that the likelihood of exploitation is high and attempts are expected shortly.
Check Point VPN serves as a cornerstone for enterprise remote access, allowing employees to securely connect to internal corporate networks via encrypted tunnels. Because of this privileged position, any flaw in the VPN gateway can grant an attacker an open door into the heart of an organization's digital infrastructure.
Technical Breakdown of the Vulnerabilities
The first flaw, CVE-2026-85102, involves the improper validation of certificate data during the VPN negotiation process. This could allow a remote attacker to execute arbitrary code on a Security Gateway. The second, CVE-2026-85103, is a heap overflow in the VPN certificate ASN.1 decoder, potentially leading to remote code execution on both Security Gateways and Security Management Servers.
| CVE ID | Vulnerability Type | Potential Impact |
|---|---|---|
| CVE-2026-85102 | Improper Validation | Arbitrary Code Execution |
| CVE-2026-85103 | Heap Overflow | Remote Code Execution (RCE) |
Affected releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, as well as legacy end-of-support (EoS) versions from R80 to R81.10. Notably, version R82.20 is confirmed to be unaffected.
Why This Matters
BozokMedia analysis shows that targeting VPN gateways is a preferred strategy for advanced persistent threat (APT) groups. By compromising the entry point, attackers bypass perimeter defenses, enabling them to steal confidential data, modify critical system settings, and disrupt entire business operations without triggering standard internal alarms.
"The window between a vulnerability disclosure and active exploitation is shrinking; patching is no longer a weekly task but a real-time necessity."
Organizations are strongly encouraged to apply Check Point LivePatch Take 24 or the latest Jumbo Hotfix Accumulators. For those utilizing 'Site-to-Site VPN' components, the NCSC recommends restricting access to a whitelist of trusted IP addresses to mitigate risk.
Frequently Asked Questions
Q1: Do I need to reboot my server after patching?
A: Users of Check Point Live Patch (CPLP) on versions R81.20, R82, and R82.10 should receive protections automatically without requiring a server reboot.
Q2: Which version is the safest to use right now?
A: Check Point VPN version R82.20 is not affected by either of these critical flaws.