Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
Recorded: Sept. 12, 2026, 3:08 p.m.
| Original | Summarized |
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent News Featured Passkey-themed phishing attacks lead to Microsoft 365 data theft Artifactory flaws chained in attacks deploying backdoor malware Trezor: 347,000 users targeted in phishing attacks after Brevo breach September Windows Server updates break Remote Desktop Services Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent Get 3 years of Surfshark VPN for $67.19 in this deal Hackers abused Claude to extract secrets from 1.8M Android apps Florida confirms DMV database breached via stolen police account Tutorials Latest How to access the Dark Web using the Tor Browser How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to use the Windows Registry Editor How to backup and restore the Windows Registry How to start Windows in Safe Mode How to remove a Trojan, Virus, Worm, or other Malware How to show hidden files in Windows 7 How to see hidden files in Windows Webinars Latest Qualys BrowserCheck STOPDecrypter AuroraDecrypter FilesLockerDecrypter AdwCleaner ComboFix RKill Junkware Removal Tool Deals Categories eLearning IT Certification Courses Gear + Gadgets Security VPNs Popular Best VPNs How to change IP address Access the dark web safely Best VPN for YouTube Forums Virus Removal Guides HomeNewsSecurityDutch NCSC: Critical Check Point VPN flaws exploitation is imminent Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent By Bill Toulas September 12, 2026 The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Related Articles: Check Point Software Bill Toulas Previous Article Post a Comment Community Rules You need to login in order to post a comment Not a member yet? Register Now You may also like: Upcoming Webinar Popular Stories September Windows Server updates break Remote Desktop Services Microsoft Excel KB5002914 update breaks copy and paste for some users New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access Sponsor Posts Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday. EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain Overdue a password health-check? Audit your Active Directory for free Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. Upcoming Webinar Follow us: Main Sections News Community Forums Useful Resources Welcome Guide Company About BleepingComputer Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved Login Username Password Remember Me Sign in anonymously Sign in with Twitter Not a member yet? Register Now Help us understand the problem. What is going on with this comment? Spam Abusive or Harmful Inappropriate content Strong language Other Read our posting guidelinese to learn what content is prohibited. Submitting... |
The Dutch National Cyber Security Centre (NCSC) has issued a warning regarding the imminent exploitation of two critical flaws in Check Point VPN, specifically tracked as CVE-2026-85102 and CVE-2026-85103. Although no public proof-of-concept exploit has been reported, the NCSC asserts that the likelihood and potential impact of exploitation are assessed as high, anticipating that exploitation attempts are likely to occur shortly. Check Point VPN functions as an enterprise solution enabling remote employees to securely access internal networks through encrypted connections. CVE-2026-85102 involves an improper validation of certificate data during the VPN negotiation process, which could allow a remote attacker to execute arbitrary code on a Security Gateway. Furthermore, CVE-2026-85103 concerns a heap overflow within the VPN certificate ASN.1 decoder, which could permit remote code execution on both Security Gateways and Security Management Servers. The affected software releases include versions such as R81.10.x, R82, R82.10, R80 through R80.40, R81, and R81.10.x. The NCSC strongly advises organizations to apply the necessary security updates immediately to mitigate these risks. Exploitation of these vulnerabilities could grant an attacker full control over a system, enabling them to view or modify confidential data and disrupt operational functions. In addition to applying patches, the agency recommends that system administrators modify VPN rules to restrict access to specific, trusted IP addresses for those utilizing the Site-to-Site VPN component. Information regarding the fixes is available through Check Point LivePatch Take 24 for specific versions of R81.20, R82, and R82.10. These fixes are also incorporated in later updates, including the R82 Jumbo Hotfix Accumulator Take 44 or later, R82 Jumbo Hotfix Accumulator Take 126 or later, and R81.20 Jumbo Hotfix Accumulator Take 166 or later. Users of Check Point VPN version R82.20 are reportedly unaffected by either of these flaws. Users who have implemented Check Point Live Patch (CPLP) should be aware that they may have received all available protections for these vulnerabilities since the initial advisory, and these fixes should be applied without requiring a server reboot. It is important for CPLP users to verify their protection status, as this automatic mitigation is not universally available across all configurations or versions. Bill Toulas, a technology writer and infosec reporter, reported on this critical security advisory. |