Dutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk
Dutch NCSC warns two CVSS 9.8 Check Point VPN flaws enable unauthenticated RCE; patch and restrict access before exploitation begins.
The Dutch NCSC warns that CVE-2026-85102, a security-check bypass in the VPN negotiation process, and CVE-2026-85103, a heap overflow in the certificate ASN.1 decoder, both carry a CVSS score of 9.8 and allow unauthenticated remote code execution on Check Point Security Gateways and Security Management Servers. Check Point fixed the flaws on September 9 via advisories sk1000117 and sk1000118, covering R81.20, R82, R82.10, R81.10.x, R82.00.x plus end-of-support versions R80 through R81.10; R82.20 is unaffected. No public proof-of-concept exists, but the NCSC rates exploitation likelihood as high and recommends patching immediately via LivePatch Take 24 or Jumbo Hotfix and restricting VPN access to trusted IPs.
- Two CVSS 9.8 flaws allow unauthenticated RCE on Check Point VPN gateways
- CVE-2026-85102 bypasses VPN negotiation checks; CVE-2026-85103 is an ASN.1 decoder heap overflow
- Fixed September 9 via advisories sk1000117 and sk1000118; R82.20 unaffected
- No public PoC yet, but NCSC expects exploitation attempts soon
- Site-to-Site VPN users should disable implied rules and restrict access to trusted IPs
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-85102 | Unauthenticated RCE in Check Point Quantum Security Gateway via certificate flaw CVE-2026-85102 is an improper certificate trust-validation flaw (CWE-295) in the VPN negotiation code of Check Point Quantum Security Gateways. An unauthenticated remote attacker who can reach the gateway's VPN service can trigger the flaw during VPN negotiation, where certificates involved in the exchange are not properly validated, and achieve code execution on the gateway. Successful exploitation yields arbitrary code execution on the gateway with high impact on confidentiality, integrity, and availability (CVSS 9.8), amounting to full compromise of the security gateway. The affected population is organizations running Quantum Security Gateways with VPN services reachable from untrusted networks. As of the available reporting there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation is confirmed; the issue was disclosed alongside a second, similarly rated (9.8) Check Point VPN certificate-validation RCE flaw. Do: Upgrade Quantum Security Gateways to the fixed versions listed in Check Point's advisory (AV26-902) as soon as they are published, prioritizing internet-facing VPN gateways. Until patched, restrict exposure of VPN negotiation endpoints to trusted networks and monitor VPN services for anomalous handshake activity. Inventory which gateways in your estate expose VPN services publicly and treat those as the highest-priority targets. | 9.8 | — |
| largetens of thousands of internet-exposed Quantum VPN gateways (est.); total Check Point installed base plausibly in the hundreds of thousands of appliances/sites | ||
| CVE-2026-85103 | Unauthenticated RCE in Check Point Quantum VPN Certificate ASN.1 Decoding CVE-2026-85103 is a heap-based buffer overflow (CWE-122) in the ASN.1 certificate-decoding code used by Check Point's VPN implementation, rated 9.8 Critical with a network-exploitable, unauthenticated, low-complexity vector. An unauthenticated remote attacker can trigger the flaw by sending crafted certificate data that the VPN service parses during connection handling, causing heap corruption that allows arbitrary code execution on the target system. Successful exploitation grants the attacker code execution with high confidentiality, integrity, and availability impact, which on security gateways and management servers could mean control of the security infrastructure itself. Any organization running Check Point Quantum Security Management or Quantum Security Gateway systems that process VPN certificate traffic is potentially affected, and the advisory set indicates this flaw was disclosed alongside a second, similarly rated 9.8 VPN certificate vulnerability (Check Point advisory AV26-902). There is no evidence of exploitation so far: the flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known. Do: Patch promptly: because this is an unauthenticated, network-reachable 9.8-rated RCE in the VPN path, upgrade Quantum Security Management and Quantum Security Gateway deployments per Check Point's advisory (referenced as AV26-902), and check your current software versions against the affected/fixed ranges listed there, which are not specified in the data available here. Until patched, restrict access to exposed VPN and management interfaces to trusted source IPs where possible and monitor VPN endpoints for anomalous connection or crash behavior. Inventory all Quantum appliances and management servers, since the flaw affects both product lines and was disclosed together with a second 9.8 VPN certificate flaw. | 9.8 | — |
| largelikely tens of thousands (order of magnitude 10k–100k) of deployed Quantum gateways/management servers, of which a substantial share expose VPN endpoints to… |
Full article524 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 14, 2026

Two critical Check Point VPN flaws score 9.8 and could enable remote code execution. Patch now and restrict VPN access before exploitation begins.
The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN products, both rated CVSS score of 9.8, could soon be actively exploited. If you use Check Point VPN, you should patch it immediately.
CVE‑2026‑85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks and run their own code on the gateway. CVE‑2026‑85103 is a heap overflow in the certificate ASN.1 decoder that also leads to remote code execution on Security Gateways and Security Management Servers.
Both vulnerabilities can be triggered by external attackers, and while no public proof‑of‑concept has surfaced yet, the NCSC explicitly rates the likelihood of exploitation and the potential damage as high.
“There are 2 critical vulnerabilities in Check Point VPN products with the attributes CVE-2026-85102 and CVE-2026-85103. These are 2 serious vulnerabilities with a CVSS score of 9.8.” reads the alert. “The NCSC assesses the likelihood of exploitation and potential damage as high and expects that attempts at exploitation will occur soon; therefore, the advice is to install the updates as soon as possible.”
An attacker can take over the system, read or change confidential data, and disrupt operations. In practice, that means your VPN appliance stops being a secure entry point and starts being a beachhead inside your network.
Check Point addressed the flaws on September 9 with the release of the advisories sk1000117 and sk1000118. The affected releases span R81.20, R82, R82.10, R81.10.x and R82.00.x, plus end‑of‑support versions from R80 through R81.10. R82.20 is not affected.
For supported versions, Check Point provides fixes through LivePatch Take 24 or specific Jumbo Hotfix updates, depending on the version you use.
If you use LivePatch with R81.20, R82 or R82.10, your system may already be protected without a reboot. However, you should check your setup to make sure. LivePatch does not cover every version or configuration, so don’t assume you are protected.
The NCSC’s advice is straightforward: install the updates as soon as possible. For organizations using Site‑to‑Site VPN, it also recommends tightening the ruleset: disable implied rules and restrict VPN access to specific, trusted IP addresses instead of leaving it wide open. If you’re not sure whether you’re running a vulnerable version, talk to your IT provider now, not after the first IOC shows up in your logs.
“The NCSC advises installing these updates as soon as possible. For organizations using Site-to-Site VPN, it is recommended to adjust certain VPN rules, such as disabling implied rules and restricting VPN access to specific IP addresses.” concludes the alert. “Contact your IT service provider if you are unsure whether you are using a vulnerable version. If necessary, ask for assistance in implementing the recommended measures.”
This isn’t a “schedule a change window next month” situation. It’s a “verify, patch, restrict, and move on before someone else decides your VPN is their new favorite initial access broker” kind of week.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Check Point)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/199015/security/dutch-ncsc-warns-critical-check-point-vpn-flaws-put-networks-at-risk.html