Vulnerabilities

Dutch NCSC Expects Mass Exploitation of Two Critical Check Point VPN Flaws

Dutch NCSC Expects Mass Exploitation of Two Critical Check Point VPN Flaws

The Netherlands’ Nationaal Cyber Security Centrum told organisations on 10 September to patch two Check Point VPN vulnerabilities before anyone has published working exploit code for them. The agency rates both the likelihood of exploitation and the potential damage as high and says it expects abuse attempts on a large scale soon. Both flaws, CVE-2026-85102 and CVE-2026-85103, carry a CVSS score of 9.8 and let an unauthenticated remote attacker run code on a Check Point Security Gateway.

Check Point released the fixes on 9 September alongside two advisories, sk1000117 and sk1000118. The company says its own research team found both issues and that it has seen no evidence of exploitation. CERT-EU issued a critical advisory the following day and told organisations to prioritise internet-facing perimeter appliances.

Two Ways Into the Same Certificate Path

CVE-2026-85102 is an improper validation of certificate data during VPN negotiation. The gateway never properly establishes whether a certificate presented by a remote peer can be trusted and that is enough for an attacker without credentials to reach code execution on the Security Gateway. Remote Access VPN and Site-to-Site VPN deployments are both in scope which covers gateway-to-gateway tunnels and third-party interconnects, not just the portal your staff log in to.

CVE-2026-85103 is a heap overflow in the ASN.1 decoder that reads VPN certificates. A crafted certificate can corrupt memory during parsing. The reach is wider on this one: Check Point lists both the Security Gateway and the Security Management Server as affected. The management server is the machine that writes and distributes policy to every gateway in the estate.

Check Point Will Not Say What the Specific Conditions Are

Check Point’s notice to customers says the flaws could allow unauthenticated remote code execution under specific conditions. It does not name those conditions. The company has published no indicators of compromise either, on the grounds that it has no exploitation to point at.

That combination is awkward for anyone trying to scope their own exposure. A vendor that assigns its own findings a 9.8 and then withholds the preconditions forces every customer to plan for the worst case. That is probably the right assumption. It is not a substitute for the detail. The Dutch NCSC appears to have reached the same conclusion and escalated anyway.

One useful detail did surface in Check Point’s CheckMates community thread. Asked whether gateways with the VPN software blade switched off are affected by CVE-2026-85103, a Check Point staff member replied that the issue concerns certificate processing so it could in theory be triggered in an environment with no VPN in use but with VPN certificates present according to The Hacker News. Switching off the blade is not a scoping shortcut.

Live Patch Does Not Reach Every Affected Version

The fix arrived in two forms. Live Patch Take 24 covers R81.20, R82 and R82.10 and began rolling out on 9 September and Check Point told customers in the community thread that it applies without a server reboot. The alternative is the Jumbo Hotfix Accumulator: Take 166 or later for R81.20, Take 126 or later for R82 and Take 44 or later for R82.10 plus Spark builds R82.00.10 Build 2325 and R81.10.17 Build 4968 or later.

The gap sits at the older end. The affected list also takes in the end-of-support branches R80 through R80.40, R81 and R81.10 and BleepingComputer reports that Live Patch is not available for anything outside R82.10, R82 and R81.20 and does not support all configurations. An organisation still running an end-of-support gateway on a public address has no automatic route to this fix at all.

R82.20 is not affected.

No Swedish Advisory Yet, and No Reason to Wait for One

CERT-EU published on 10 September. The Dutch NCSC published on 10 September. CERT-SE’s weekly letter of 11 September covered the Cyber Resilience Act reporting duty, the September patch round and the Cisco Secure Firewall Management Center flaws that Cisco Talos has linked to three separate threat actor clusters. Check Point was not in it and as of 14 September CERT-SE has published no Check Point advisory of its own, having issued one for Citrix NetScaler and another for GitLab in the same week.

National CSIRTs choose their advisories on their own criteria and a gap is not an all-clear. Swedish organisations running Check Point gateways on public addresses already have the Dutch assessment, the CERT-EU advisory and the vendor’s own 9.8 rating in front of them. That is enough to act on.

Sweden’s Cybersäkerhetslagen (SFS 2025:1506) has applied since 15 January 2026 and the Dutch Cyberbeveiligingswet since 15 August 2026. Article 21 of NIS2 requires documented risk management measures and Article 20 puts approval and oversight of those measures on the management body. An unpatched internet-facing VPN gateway is a board file, not a line on an IT backlog.

Three Checks Before the Exploit Code Lands

  1. Inventory every Check Point Security Gateway, Spark Firewall and Security Management Server in the estate, and record the version and Jumbo Hotfix Take for each. A perimeter scan on its own will miss the management server.
  2. Verify that Live Patch actually landed. Automatic protection is a claim until inventory evidence supports it, and it does not reach R80, R81 or R81.10.
  3. For Site-to-Site estates that cannot patch today, apply Check Point’s stated mitigation, disable implied rules for VPN and define VPN access manually for UDP/500 and UDP/4500 to specific peer IP addresses.

Check Point warned customers this summer about two other zero-day vulnerabilities in its products, CVE-2026-16232 and CVE-2026-50751. This attack surface has a recent track record. Patch it this week.

References

  1. Dutch NCSC: Critical Check Point VPN Flaws Exploitation is Imminent
  2. Kritieke Kwetsbaarheden in Check Point VPN-Producten Met Actief Misbruik Verwacht
  3. Critical Vulnerabilities in Check Point Products
  4. Check Point Patches Critical VPN Vulnerabilities
  5. Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
  6. Security Advisory sk1000118
  7. CERT-SE:s veckobrev v.37

This post is also available in: Svenska

Per Häggdahl

Per Häggdahl is Head of Business Unit and CISO at eBuilder Security, with more than 20 years securing systems for banks, central banks, stock exchanges and central securities depositories, now leading the team that brings that same enterprise-grade protection to organisations of every size.