Dutch NCSC Warns Exploitation Is Imminent for Two Critical Check Point VPN Certificate RCE Flaws Patched September 9
Check Point patched two CVSS 9.8 VPN certificate flaws (CVE-2026-85102, CVE-2026-85103) enabling unauthenticated remote code execution on September 9, 2026; with no public PoC yet, the Dutch NCSC rates exploitation likelihood high, warns exploitation is…
On September 9, 2026, Check Point released emergency updates for two critical (CVSS 9.8) vulnerabilities in VPN certificate handling — CVE-2026-85102 and CVE-2026-85103 — both exploitable for unauthenticated remote code execution under specific conditions on VPN-enabled deployments. Most sources (CERT-EU, The Hacker News, Cyber Security News, SecurityWeek, BleepingComputer, Security Affairs) describe CVE-2026-85102 as improper certificate trust/data validation (CWE-295) during VPN negotiation, while Canada's Cyber Centre and GBHackers characterize it as an authentication bypass in Remote Access and Site-to-Site VPN; all agree it enables unauthenticated RCE on Security Gateways. CVE-2026-85103 is a heap-based buffer overflow (CWE-122) in ASN.1 certificate decoding that enables RCE on Security Gateways (Quantum Security Gateways per The Hacker News) and Security Management Server. The flaws affect Security Gateway, Security Management Server, and Spark Firewall deployments configured with Remote Access or Site-to-Site VPN; affected versions are disputed across sources — CERT-EU says R80 through R82.10; The Hacker News and SecurityWeek list R81.20, R82, and R82.10; BleepingComputer and Security Affairs add R81.10.x and R82.00.x plus end-of-support versions R80 through R81.10 (Cyber Security News cites EoS R80.40 and R81); all agree R82.20 is unaffected. Check Point found both flaws through internal research and reports no evidence of in-the-wild exploitation and no public PoC; Cyber Security News notes they are unrelated to the actively exploited IKEv1 bypass CVE-2026-50751. Fixes shipped September 9 via LivePatch (Take 24 per BleepingComputer) or, for administrators without it, Jumbo Hotfix Accumulator builds (R82.10 Take 44+, R82 Take 126+, R81.20 Take 166+) under Check Point advisories sk1000117 and sk1000118. Canada's Cyber Centre issued advisory AV26-902 on September 9 and CERT-EU published advisory 2026-012 on September 10 urging immediate hotfix application, prioritizing internet-facing and perimeter appliances. On September 12 the Dutch NCSC assessed exploitation likelihood and impact as high and warned exploitation is imminent; September 14 reports add that the NCSC expects large-scale exploitation attempts soon despite the absence of public exploit code. Interim mitigations include restricting Site-to-Site VPN UDP ports 500 and 4500 to known/trusted peer IPs, manually defining VPN rules (not applicable to locally managed Spark Firewalls), disabling…
- CVE-2026-85102 (CVSS 9.8): most sources describe improper certificate trust/data validation (CWE-295) during VPN negotiation; Canada's Cyber Centre and GBHackers characterize it as an authentication bypass in Remote Access and Site-to-Site…
- CVE-2026-85103 (CVSS 9.8): heap-based buffer overflow (CWE-122) in ASN.1 certificate decoding, enabling RCE on Security Gateways (Quantum Security Gateways per The Hacker News) and Security Management Server.
- Affected products: Security Gateway, Security Management Server, and Spark Firewall with Remote Access or Site-to-Site VPN configured; R82.20 is not affected.
- Affected versions are disputed: CERT-EU says R80 through R82.10; The Hacker News and SecurityWeek list R81.20, R82, R82.10; BleepingComputer and Security Affairs add R81.10.x, R82.00.x plus end-of-support R80–R81.10 (Cyber Security News…
- Fixes shipped September 9, 2026 via LivePatch Take 24 or Jumbo Hotfix Accumulator builds (R82.10 Take 44+, R82 Take 126+, R81.20 Take 166+); Check Point advisories sk1000117 and sk1000118 per Security Affairs.
- Check Point found both flaws internally; no evidence of in-the-wild exploitation and no public PoC; Cyber Security News notes the flaws are unrelated to the actively exploited IKEv1 bypass CVE-2026-50751.
- Dutch NCSC (September 12) rates exploitation likelihood and impact as high, warns exploitation is imminent, and — per September 14 reports — expects large-scale exploitation attempts soon.
- Government advisories: Canadian Centre for Cyber Security AV26-902 (September 9) and CERT-EU 2026-012 (September 10) urging immediate hotfixes, prioritizing internet-facing and perimeter appliances.
Coverage timelineoldest first · each row is one article
- · 6d agoCheck Point security advisory (AV26-902)
Canadian Centre for Cyber Security· 52
Canada's Cyber Centre issued advisory AV26-902 warning of two Check Point RCE flaws, including VPN authentication bypass CVE-2026-85102.
- · 5d ago2026-012: Critical Vulnerabilities in Check Point Products
CERT-EU Advisories· 80
Check Point issued emergency hotfixes for two CVSS 9.8 flaws (CVE-2026-85102, CVE-2026-85103) enabling unauthenticated RCE on VPN-enabled gateways.
- · 5d agoCheck Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
The Hacker News· 62
Check Point patched two 9.8-rated VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, enabling unauthenticated remote code execution; no exploitation observed yet.
- · 5d agoCritical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks
Cyber Security News· 70
Check Point patched two critical VPN flaws, CVE-2026-85102 and CVE-2026-85103 (CVSS 9.8), allowing unauthenticated RCE on Security Gateways.
- · 4d agoCritical Check Point VPN Flaws Let Unauthenticated Attackers Execute Remote Code
GBHackers· 65
Check Point fixed critical unauthenticated RCE flaws CVE-2026-85102 and CVE-2026-85103 in its VPN gateways; no exploitation observed yet.
- · 4d agoCheck Point Patches Critical VPN Vulnerabilities
SecurityWeek· 60
Check Point patches two critical unauthenticated RCE flaws (CVE-2026-85102, CVE-2026-85103) in VPN gateways and firewalls; no exploitation observed.
- · 3d agoDutch NCSC: Critical Check Point VPN flaws exploitation is imminent
BleepingComputer· 78
Dutch NCSC warns exploitation is imminent for critical Check Point VPN RCE flaws CVE-2026-85102 and CVE-2026-85103, urging immediate patching of Security Gateways.
- · 1d agoNCSC Warns of Critical Check Point VPN Flaws as Large-Scale Exploitation Is Expected
Cyber Security News· 74
Dutch NCSC warns of two critical CVSS 9.8 Check Point VPN flaws enabling unauthenticated remote code execution, urging immediate patching before mass exploitation.
- · 1d agoDutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at Risk
Security Affairs· 68
Dutch NCSC warns two CVSS 9.8 Check Point VPN flaws enable unauthenticated RCE; patch and restrict access before exploitation begins.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-16232 | Authentication Bypass in Check Point SmartConsole Grants Full Admin Access Check Point SmartConsole, the administrative client used to manage Quantum Security Management and Multi-Domain Security Management, contains an authentication bypass (CWE-287) in its login process that allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. Exploitation is possible when the Management Server IP address is reachable from the internet and the configuration does not restrict Trusted Clients. A successful attacker can modify security policies and security configurations, effectively taking control of firewall management. Any organization running an internet-exposed Check Point management server without Trusted Client restrictions is affected, though Check Point reports exploitation has impacted only a very small number of customers. The flaw was added to CISA's KEV on 2026-07-22, is actively exploited, and press reports indicate public proof-of-concept code has been released. Do: Apply the fix released in Check Point's advisory for CVE-2026-16232 by updating SmartConsole and the associated Quantum/MDS management software; no fixed version numbers were provided in this data, so confirm them against the vendor bulletin. As an interim mitigation, restrict internet access to the Management Server IP address and configure Trusted Clients so SmartConsole connections are accepted only from known administrator addresses. Review management logs for unexpected logins, unauthenticated token issuance, or unfamiliar administrator sessions, and complete remediation per CISA BOD 26-04 given the KEV listing. | 9.3 | 72% | KEV |
| largeplausibly tens of thousands of Check Point management deployments, though the vulnerable subset is only those with an internet-exposed Management Server and no… | |
| CVE-2026-50751 | Unauthenticated IKEv1 VPN Auth Bypass in Check Point Security Gateways Check Point has disclosed CVE-2026-50751, a critical (CVSS 9.3) improper authentication flaw (CWE-287) in the certificate validation logic for Remote Access and Mobile Access VPN when the deprecated IKEv1 key exchange is used. An unauthenticated remote attacker can exploit this logic flow weakness during IKEv1 negotiation to bypass user authentication entirely. Successful exploitation lets the attacker establish a remote access VPN connection without a valid user password, gaining access to the organization's internal network resources (high confidentiality impact per the CVSS score). Any organization running a Check Point Security Gateway on Gaia OS or Gaia Embedded with IKEv1-based Remote Access/Mobile Access configured is affected; specific affected and fixed versions are in Check Point's advisory. The flaw is being exploited in the wild — it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-08 with known ransomware use and an EPSS of 83.8% — and it was disclosed alongside other critical Check Point VPN certificate flaws per recent headlines. Do: Upgrade affected Security Gateways to the fixed releases identified in Check Point's advisory (version numbers are not specified in the source data), prioritizing internet-facing VPN gateways; as an interim mitigation, move Remote Access/Mobile Access clients to IKEv2 or disable IKEv1. Review VPN authentication logs for sessions established without valid credentials, given known in-the-wild and ransomware exploitation. Federal agencies must apply mitigations per BOD 22-01, and defenders should beware of fake 'public PoC' repositories spreading malware (ChocoPoC RAT), since no legitimate public PoC is known. | 9.3 | 84% | KEV ransomware PoC |
| massplausibly on the order of 100,000+ internet-exposed Check Point gateways, with the IKEv1-affected subset likely tens of thousands of sites (estimate) | |
| CVE-2026-85102 | Unauthenticated RCE in Check Point Quantum Security Gateway via certificate flaw CVE-2026-85102 is an improper certificate trust-validation flaw (CWE-295) in the VPN negotiation code of Check Point Quantum Security Gateways. An unauthenticated remote attacker who can reach the gateway's VPN service can trigger the flaw during VPN negotiation, where certificates involved in the exchange are not properly validated, and achieve code execution on the gateway. Successful exploitation yields arbitrary code execution on the gateway with high impact on confidentiality, integrity, and availability (CVSS 9.8), amounting to full compromise of the security gateway. The affected population is organizations running Quantum Security Gateways with VPN services reachable from untrusted networks. As of the available reporting there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation is confirmed; the issue was disclosed alongside a second, similarly rated (9.8) Check Point VPN certificate-validation RCE flaw. Do: Upgrade Quantum Security Gateways to the fixed versions listed in Check Point's advisory (AV26-902) as soon as they are published, prioritizing internet-facing VPN gateways. Until patched, restrict exposure of VPN negotiation endpoints to trusted networks and monitor VPN services for anomalous handshake activity. Inventory which gateways in your estate expose VPN services publicly and treat those as the highest-priority targets. | 9.8 | — |
| largetens of thousands of internet-exposed Quantum VPN gateways (est.); total Check Point installed base plausibly in the hundreds of thousands of appliances/sites | ||
| CVE-2026-85103 | Unauthenticated RCE in Check Point Quantum VPN Certificate ASN.1 Decoding CVE-2026-85103 is a heap-based buffer overflow (CWE-122) in the ASN.1 certificate-decoding code used by Check Point's VPN implementation, rated 9.8 Critical with a network-exploitable, unauthenticated, low-complexity vector. An unauthenticated remote attacker can trigger the flaw by sending crafted certificate data that the VPN service parses during connection handling, causing heap corruption that allows arbitrary code execution on the target system. Successful exploitation grants the attacker code execution with high confidentiality, integrity, and availability impact, which on security gateways and management servers could mean control of the security infrastructure itself. Any organization running Check Point Quantum Security Management or Quantum Security Gateway systems that process VPN certificate traffic is potentially affected, and the advisory set indicates this flaw was disclosed alongside a second, similarly rated 9.8 VPN certificate vulnerability (Check Point advisory AV26-902). There is no evidence of exploitation so far: the flaw is not in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept is known. Do: Patch promptly: because this is an unauthenticated, network-reachable 9.8-rated RCE in the VPN path, upgrade Quantum Security Management and Quantum Security Gateway deployments per Check Point's advisory (referenced as AV26-902), and check your current software versions against the affected/fixed ranges listed there, which are not specified in the data available here. Until patched, restrict access to exposed VPN and management interfaces to trusted source IPs where possible and monitor VPN endpoints for anomalous connection or crash behavior. Inventory all Quantum appliances and management servers, since the flaw affects both product lines and was disclosed together with a second 9.8 VPN certificate flaw. | 9.8 | — |
| largelikely tens of thousands (order of magnitude 10k–100k) of deployed Quantum gateways/management servers, of which a substantial share expose VPN endpoints to… |