Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
Dutch NCSC warns exploitation is imminent for critical Check Point VPN RCE flaws CVE-2026-85102 and CVE-2026-85103, urging immediate patching of Security Gateways.
The Dutch NCSC assesses the likelihood and impact of exploitation as high for two critical Check Point VPN flaws, though no public PoC exploit has been reported. CVE-2026-85102 is improper validation of certificate data during VPN negotiation, and CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder; both enable remote code execution on Security Gateways, the latter also on Security Management Servers. Affected releases span R81.20, R82, R82.10, R81.10.x, R82.00.x and EoS versions R80 through R81.10, while R82.20 is unaffected. Check Point shipped fixes on September 9 via LivePatch Take 24 and Jumbo Hotfix Accumulator takes, and NCSC advises restricting Site-to-Site VPN rules to trusted IPs.
- CVE-2026-85102: improper certificate data validation enables remote code execution on Security Gateways during VPN negotiation
- CVE-2026-85103: heap overflow in VPN certificate ASN.1 decoder allows RCE on gateways and management servers
- Fixes shipped September 9 via LivePatch Take 24 and Jumbo Hotfix Accumulator takes for R81.20 through R82.10
- NCSC advises restricting Site-to-Site VPN rules to trusted IP addresses and applying updates urgently
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-85102 | Unauthenticated RCE in Check Point Quantum Security Gateway via certificate flaw CVE-2026-85102 is an improper certificate trust-validation flaw (CWE-295) in the VPN negotiation code of Check Point Quantum Security Gateways. An unauthenticated remote attacker who can reach the gateway's VPN service can trigger the flaw during VPN negotiation, where certificates involved in the exchange are not properly validated, and achieve code execution on the gateway. Successful exploitation yields arbitrary code execution on the gateway with high impact on confidentiality, integrity, and availability (CVSS 9.8), amounting to full compromise of the security gateway. The affected population is organizations running Quantum Security Gateways with VPN services reachable from untrusted networks. As of the available reporting there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation is confirmed; the issue was disclosed alongside a second, similarly rated (9.8) Check Point VPN certificate-validation RCE flaw. Do: Upgrade Quantum Security Gateways to the fixed versions listed in Check Point's advisory (AV26-902) as soon as they are published, prioritizing internet-facing VPN gateways. Until patched, restrict exposure of VPN negotiation endpoints to trusted networks and monitor VPN services for anomalous handshake activity. Inventory which gateways in your estate expose VPN services publicly and treat those as the highest-priority targets. | 9.8 | — |
| largetens of thousands of internet-exposed Quantum VPN gateways (est.); total Check Point installed base plausibly in the hundreds of thousands of appliances/sites | ||
| CVE-2026-85103 | Unauthenticated RCE in Check Point Quantum VPN Certificate ASN.1 Decoding CVE-2026-85103 is a heap-based buffer overflow (CWE-122) in the ASN.1 certificate-decoding code used by Check Point's VPN implementation, rated 9.8 Critical with a network-exploitable, unauthenticated, low-complexity vector. An unauthenticated remote attacker can trigger the flaw by sending crafted certificate data that the VPN service parses during connection handling, causing heap corruption that allows arbitrary code execution on the target system. Successful exploitation grants the attacker code execution with high confidentiality, integrity, and availability impact, which on security gateways and management servers could mean control of the security infrastructure itself. Any organization running Check Point Quantum Security Management or Quantum Security Gateway systems that process VPN certificate traffic is potentially affected, and the advisory set indicates this flaw was disclosed alongside a second, similarly rated 9.8 VPN certificate vulnerability (Check Point advisory AV26-902). There is no evidence of exploitation so far: the flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known. Do: Patch promptly: because this is an unauthenticated, network-reachable 9.8-rated RCE in the VPN path, upgrade Quantum Security Management and Quantum Security Gateway deployments per Check Point's advisory (referenced as AV26-902), and check your current software versions against the affected/fixed ranges listed there, which are not specified in the data available here. Until patched, restrict access to exposed VPN and management interfaces to trusted source IPs where possible and monitor VPN endpoints for anomalous connection or crash behavior. Inventory all Quantum appliances and management servers, since the flaw affects both product lines and was disclosed together with a second 9.8 VPN certificate flaw. | 9.8 | — |
| largelikely tens of thousands (order of magnitude 10k–100k) of deployed Quantum gateways/management servers, of which a substantial share expose VPN endpoints to… |
Full article444 words · extracted from bleepingcomputer.com · click to collapse

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
Although no public proof-of-concept (PoC) exploit has been reported, the agency is urging organizations to install the security updates addressing the two issues as soon as possible.
“The NCSC assesses the likelihood of exploitation and the potential impact as high and expects exploitation attempts to occur soon,” the NCSC warns.
Check Point VPN is an enterprise solution that allows remote employees to securely connect to their company's internal network via encrypted connections.
On September 9, Check Point issued fixes for the flaws along with separate security advisories describing them: sk1000117 and sk1000118.
CVE-2026-85102 is an improper validation of certificate data during VPN negotiation that a remote attacker could exploit to execute arbitrary code on a Security Gateway.
CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder that could allow remote code execution on Security Gateways and Security Management Servers.
Affected releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, along with the end-of-support (EoS) versions R80 through R80.40, R81, and R81.10.
Both flaws are fixed by Check Point LivePatch Take 24 for R81.20, R82, and R82.10, while fixes are also included in the following versions:
- R82.10 Jumbo Hotfix Accumulator Take 44 or later
- R82 Jumbo Hotfix Accumulator Take 126 or later
- R81.20 Jumbo Hotfix Accumulator Take 166 or later
- Spark R82.00.10 Build 2325 or later
- Spark R81.10.17 Build 4968 or later
Check Point VPN version R82.20 is not affected by either flaw.
NCSC warned that exploitation of the flaws could allow an attacker to take full control of a system, view or modify confidential data, and disrupt operations.
The organization urges system administrators to apply the security updates as soon as possible. At the same time, for those using the ‘Site-to-Site VPN’ component, the advice is to modify VPN rules to limit access to specific, trusted IP addresses.
According to a post in Check Point’s community forums, users of Check Point Live Patch (CPLP) should have received all available protections for the two flaws since September 9, and those fixes should apply even without a server reboot.
CPLP users should check if they are protected by this automatic mitigation, as it is not available for versions other than R82.10, R82, and R81.20 and doesn’t support all configurations.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/