LmCast :: Stay tuned in

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Recorded: Sept. 12, 2026, 3:08 p.m.

Original Summarized

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

News

Featured
Latest

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Artifactory flaws chained in attacks deploying backdoor malware

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

September Windows Server updates break Remote Desktop Services

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Get 3 years of Surfshark VPN for $67.19 in this deal

Hackers abused Claude to extract secrets from 1.8M Android apps

Florida confirms DMV database breached via stolen police account

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityDutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

By Bill Toulas

September 12, 2026
10:14 AM
0

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
Although no public proof-of-concept (PoC) exploit has been reported, the agency is urging organizations to install the security updates addressing the two issues as soon as possible.
“The NCSC assesses the likelihood of exploitation and the potential impact as high and expects exploitation attempts to occur soon,” the NCSC warns.
Check Point VPN is an enterprise solution that allows remote employees to securely connect to their company's internal network via encrypted connections.
On September 9, Check Point issued fixes for the flaws along with separate security advisories describing them: sk1000117 and sk1000118.
CVE-2026-85102 is an improper validation of certificate data during VPN negotiation that a remote attacker could exploit to execute arbitrary code on a Security Gateway.
CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder that could allow remote code execution on Security Gateways and Security Management Servers.
Affected releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, along with the end-of-support (EoS) versions R80 through R80.40, R81, and R81.10.
Both flaws are fixed by Check Point LivePatch Take 24 for R81.20, R82, and R82.10, while fixes are also included in the following versions:
R82.10 Jumbo Hotfix Accumulator Take 44 or later
R82 Jumbo Hotfix Accumulator Take 126 or later
R81.20 Jumbo Hotfix Accumulator Take 166 or later
Spark R82.00.10 Build 2325 or later
Spark R81.10.17 Build 4968 or later
Check Point VPN version R82.20 is not affected by either flaw.
NCSC warned that exploitation of the flaws could allow an attacker to take full control of a system, view or modify confidential data, and disrupt operations.
The organization urges system administrators to apply the security updates as soon as possible. At the same time, for those using the ‘Site-to-Site VPN’ component, the advice is to modify VPN rules to limit access to specific, trusted IP addresses.
According to a post in Check Point’s community forums, users of Check Point Live Patch (CPLP) should have received all available protections for the two flaws since September 9, and those fixes should apply even without a server reboot.
CPLP users should check if they are protected by this automatic mitigation, as it is not available for versions other than R82.10, R82, and R81.20 and doesn’t support all configurations.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
HPE patches critical ArubaOS-CX remote code execution flawCritical Elementor Pro flaw exploited to take over WordPress sitesHackers exploit Sangoma Switchvox flaw to deploy reverse shellsWordPress backup plugin flaw exposes millions of sites to takeover attacksCritical Langflow flaw exploited to steal OpenAI and AWS keys

Check Point Software
Government
Netherlands
RCE
Remote Code Execution
Security Advisory
VPN
Vulnerability

Bill Toulas
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

September Windows Server updates break Remote Desktop Services

Microsoft Excel KB5002914 update breaks copy and paste for some users

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Sponsor Posts

Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Overdue a password health-check? Audit your Active Directory for free

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

The Dutch National Cyber Security Centre (NCSC) has issued a warning regarding the imminent exploitation of two critical flaws in Check Point VPN, specifically tracked as CVE-2026-85102 and CVE-2026-85103. Although no public proof-of-concept exploit has been reported, the NCSC asserts that the likelihood and potential impact of exploitation are assessed as high, anticipating that exploitation attempts are likely to occur shortly. Check Point VPN functions as an enterprise solution enabling remote employees to securely access internal networks through encrypted connections.

CVE-2026-85102 involves an improper validation of certificate data during the VPN negotiation process, which could allow a remote attacker to execute arbitrary code on a Security Gateway. Furthermore, CVE-2026-85103 concerns a heap overflow within the VPN certificate ASN.1 decoder, which could permit remote code execution on both Security Gateways and Security Management Servers. The affected software releases include versions such as R81.10.x, R82, R82.10, R80 through R80.40, R81, and R81.10.x.

The NCSC strongly advises organizations to apply the necessary security updates immediately to mitigate these risks. Exploitation of these vulnerabilities could grant an attacker full control over a system, enabling them to view or modify confidential data and disrupt operational functions. In addition to applying patches, the agency recommends that system administrators modify VPN rules to restrict access to specific, trusted IP addresses for those utilizing the Site-to-Site VPN component.

Information regarding the fixes is available through Check Point LivePatch Take 24 for specific versions of R81.20, R82, and R82.10. These fixes are also incorporated in later updates, including the R82 Jumbo Hotfix Accumulator Take 44 or later, R82 Jumbo Hotfix Accumulator Take 126 or later, and R81.20 Jumbo Hotfix Accumulator Take 166 or later. Users of Check Point VPN version R82.20 are reportedly unaffected by either of these flaws.

Users who have implemented Check Point Live Patch (CPLP) should be aware that they may have received all available protections for these vulnerabilities since the initial advisory, and these fixes should be applied without requiring a server reboot. It is important for CPLP users to verify their protection status, as this automatic mitigation is not universally available across all configurations or versions. Bill Toulas, a technology writer and infosec reporter, reported on this critical security advisory.