Critical Check Point VPN Flaws: Dutch NCSC Warns of Imminent Exploitation
The **Dutch Nationaal Cyber Security Centrum (NCSC)** has issued an urgent warning regarding two critical vulnerabilities, **CVE-2026-85102** and **CVE-2026-85103**, affecting **Check Point VPN** products. Organizations are strongly advised to apply security updates immediately, as exploitation attempts are anticipated to occur soon.

The **NCSC** has assessed the likelihood and potential impact of these flaws as high, urging rapid action from IT security professionals. **Check Point VPN** is a widely used enterprise solution, providing secure remote access for employees via encrypted connections.
### The Vulnerabilities Explained
**Check Point** released fixes for these vulnerabilities on September 9, accompanied by advisories **sk1000117** and **sk1000118**.
* **CVE-2026-85102** is an improper validation of certificate data during VPN negotiation. A remote attacker could exploit this to execute arbitrary code on a **Security Gateway**.
* **CVE-2026-85103** is a heap overflow within the VPN certificate ASN.1 decoder, which could also lead to remote code execution on **Security Gateways** and **Security Management Servers**.
Successful exploitation of these vulnerabilities could grant attackers full control over affected systems, allowing them to access or modify confidential data and disrupt operations.
### Affected Versions and Patches
The vulnerabilities impact several **Check Point VPN** releases, including R81.20, R82, R82.10, R81.10.x, and R82.00.x. End-of-support (EoS) versions from R80 through R80.40, R81, and R81.10 are also vulnerable.
Patches are available through **Check Point LivePatch Take 24** for R81.20, R82, and R82.10. Additionally, fixes are included in the following versions:
* R82.10 Jumbo Hotfix Accumulator Take 44 or later
* R82 Jumbo Hotfix Accumulator Take 126 or later
* R81.20 Jumbo Hotfix Accumulator Take 166 or later
* Spark R82.00.10 Build 2325 or later
* Spark R81.10.17 Build 4968 or later
It's important to note that **Check Point VPN** version R82.20 is not affected by either flaw.
### Recommendations for System Administrators
The **NCSC** strongly advises system administrators to apply the security updates as quickly as possible. For organizations utilizing the βSite-to-Site VPNβ component, an additional recommendation is to modify VPN rules to restrict access to only specific, trusted IP addresses.
Users of **Check Point Live Patch (CPLP)** should verify their protection status. According to a post in **Check Point**'s community forums, **CPLP** users should have received all available protections for these flaws since September 9, with fixes potentially applying without a server reboot. However, this automatic mitigation is not available for all configurations or for versions other than R82.10, R82, and R81.20.