NCSC Warns of Critical Check Point VPN Flaws as Large-Scale Exploitation Is Expected
Dutch NCSC warns of two critical CVSS 9.8 Check Point VPN flaws enabling unauthenticated remote code execution, urging immediate patching before mass exploitation.
The Dutch NCSC warned that CVE-2026-85102 and CVE-2026-85103, both rated 9.8 CVSS, allow unauthenticated remote attackers to execute arbitrary code on Check Point Quantum Security Gateway, Spark Firewall, and Security Management Server deployments when VPN is enabled. CVE-2026-85102 stems from improper certificate trust validation during VPN negotiation, while CVE-2026-85103 is a heap-based buffer overflow in ASN.1 certificate decoding. Check Point shipped emergency updates on September 9, 2026, including R82.10 Take 44, R82 Take 126, and R81.20 Take 166 or later, plus LivePatch for eligible systems. No public exploit code exists yet, but the NCSC rates exploitation likelihood high and recommends restricting UDP ports 500 and 4500 to known peers as a stopgap.
- Two CVSS 9.8 flaws enable unauthenticated RCE on internet-facing Check Point VPN gateways.
- Emergency patches and LivePatch rolled out September 9, 2026; Jumbo Hotfix Accumulators available.
- No public exploit code observed, but NCSC expects large-scale exploitation attempts soon.
- Admins should restrict UDP 500/4500 to known peer IPs and review VPN negotiation logs.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-85102 | Unauthenticated RCE in Check Point Quantum Security Gateway via certificate flaw CVE-2026-85102 is an improper certificate trust-validation flaw (CWE-295) in the VPN negotiation code of Check Point Quantum Security Gateways. An unauthenticated remote attacker who can reach the gateway's VPN service can trigger the flaw during VPN negotiation, where certificates involved in the exchange are not properly validated, and achieve code execution on the gateway. Successful exploitation yields arbitrary code execution on the gateway with high impact on confidentiality, integrity, and availability (CVSS 9.8), amounting to full compromise of the security gateway. The affected population is organizations running Quantum Security Gateways with VPN services reachable from untrusted networks. As of the available reporting there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation is confirmed; the issue was disclosed alongside a second, similarly rated (9.8) Check Point VPN certificate-validation RCE flaw. Do: Upgrade Quantum Security Gateways to the fixed versions listed in Check Point's advisory (AV26-902) as soon as they are published, prioritizing internet-facing VPN gateways. Until patched, restrict exposure of VPN negotiation endpoints to trusted networks and monitor VPN services for anomalous handshake activity. Inventory which gateways in your estate expose VPN services publicly and treat those as the highest-priority targets. | 9.8 | — |
| largetens of thousands of internet-exposed Quantum VPN gateways (est.); total Check Point installed base plausibly in the hundreds of thousands of appliances/sites | ||
| CVE-2026-85103 | Unauthenticated RCE in Check Point Quantum VPN Certificate ASN.1 Decoding CVE-2026-85103 is a heap-based buffer overflow (CWE-122) in the ASN.1 certificate-decoding code used by Check Point's VPN implementation, rated 9.8 Critical with a network-exploitable, unauthenticated, low-complexity vector. An unauthenticated remote attacker can trigger the flaw by sending crafted certificate data that the VPN service parses during connection handling, causing heap corruption that allows arbitrary code execution on the target system. Successful exploitation grants the attacker code execution with high confidentiality, integrity, and availability impact, which on security gateways and management servers could mean control of the security infrastructure itself. Any organization running Check Point Quantum Security Management or Quantum Security Gateway systems that process VPN certificate traffic is potentially affected, and the advisory set indicates this flaw was disclosed alongside a second, similarly rated 9.8 VPN certificate vulnerability (Check Point advisory AV26-902). There is no evidence of exploitation so far: the flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known. Do: Patch promptly: because this is an unauthenticated, network-reachable 9.8-rated RCE in the VPN path, upgrade Quantum Security Management and Quantum Security Gateway deployments per Check Point's advisory (referenced as AV26-902), and check your current software versions against the affected/fixed ranges listed there, which are not specified in the data available here. Until patched, restrict access to exposed VPN and management interfaces to trusted source IPs where possible and monitor VPN endpoints for anomalous connection or crash behavior. Inventory all Quantum appliances and management servers, since the flaw affects both product lines and was disclosed together with a second 9.8 VPN certificate flaw. | 9.8 | — |
| largelikely tens of thousands (order of magnitude 10k–100k) of deployed Quantum gateways/management servers, of which a substantial share expose VPN endpoints to… |
Full article525 words · extracted from cybersecuritynews.com · click to collapse
The Dutch National Cyber Security Center (NCSC) has issued an urgent warning over two critical vulnerabilities in Check Point VPN products, saying it expects large-scale exploitation attempts in the near term.
Organizations using affected Check Point gateways, management systems, or Spark Firewall products should deploy the available fixes immediately.
Tracked as CVE-2026-85102 and CVE-2026-85103, both flaws carry a CVSS severity score of 9.8 out of 10. The vulnerabilities can allow an unauthenticated remote attacker to execute arbitrary code, creating a serious risk for internet-facing VPN infrastructure.
Check Point VPN products commonly connect employees, offices, and networks securely over the internet. Because these systems sit at the network perimeter and often have privileged access to internal resources, a successful compromise could give attackers a path into enterprise environments.
CVE-2026-85102 affects the VPN negotiation process in Check Point Quantum Security Gateway devices. The issue stems from improper validation of certificate trust data during VPN connection setup.
NCSC Warns of Check Point VPN Flaws Exploitation
An external attacker may exploit the flaw without valid credentials, bypass authentication checks, and execute arbitrary code on a vulnerable Security Gateway.
The vulnerability affects Security Gateway and Check Point Spark Firewall products when Remote Access VPN or Site-to-Site VPN is enabled.
The second vulnerability, CVE-2026-85103, is a heap-based buffer overflow in the ASN.1 decoding flow for VPN certificates. ASN.1 is a data format commonly used in digital certificates.
A specially crafted certificate structure could trigger the memory corruption issue and enable remote code execution. Unlike the first flaw, this issue can affect Check Point Security Management Server deployments as well as Security Gateway and Spark Firewall products.
The NCSC said it has not seen public exploit code for the vulnerabilities, but assessed both the likelihood of exploitation and the potential impact as high.
The agency expects attackers to begin attempting widespread exploitation soon, making patching a priority rather than routine maintenance.
Successful exploitation could allow a threat actor to take control of an exposed appliance, access or alter confidential information, move further into connected networks, or disrupt business operations. A compromised VPN gateway can be especially valuable to attackers because it may provide trusted access to internal systems.
Check Point released emergency updates on September 9, 2026. Supported deployments should install the latest Jumbo Hotfix Accumulator, including R82.10 Take 44 or later, R82 Take 126 or later, and R81.20 Take 166 or later. Check Point LivePatch protection also began rolling out on September 9 for eligible systems.
For Site-to-Site VPN environments, administrators should also turn off implied VPN rules and explicitly limit UDP port 500 and UDP port 4500 access to known peer IP addresses. This reduces unnecessary exposure while patches are being validated and deployed.
Organizations should identify every externally reachable Check Point VPN appliance, confirm the installed software release and hotfix level, apply the appropriate update, and review logs for suspicious VPN negotiation or certificate-processing activity.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/ncsc-warns-check-point-vpn-flaws-exploitation/