NCSC Warns of Critical Check Point VPN Flaws, Exploitation Expected
Key Takeaways The Dutch National Cyber Security Center (NCSC) has issued a critical warning regarding two severe vulnerabilities in Check Point VPN products. These flaws, CVE-2026-85102 and...
Key Takeaways
- The Dutch National Cyber Security Center (NCSC) has issued a critical warning regarding two severe vulnerabilities in Check Point VPN products.
- These flaws, CVE-2026-85102 and CVE-2026-85103, both carry a CVSS score of 9.8, indicating extreme severity.
- Successful exploitation could allow unauthenticated remote code execution on affected Security Gateways, Management Servers, and Spark Firewall products.
- Check Point released emergency patches on September 9, 2026, and organizations are urged to update immediately due to expected widespread exploitation.
NCSC Issues Urgent Alert on Critical Check Point VPN Flaws
The Dutch National Cyber Security Center (NCSC) has released an urgent advisory concerning two highly critical vulnerabilities impacting various Check Point VPN products. The agency anticipates that these flaws will be actively exploited on a large scale in the immediate future, prompting an urgent call for organizations to apply available security fixes.
Table Of Content
Entities utilizing Check Point gateways, management systems, or Spark Firewall products are strongly advised to deploy the necessary patches without delay. Both vulnerabilities, identified as CVE-2026-85102 and CVE-2026-85103, have been assigned a CVSS severity score of 9.8 out of 10. These critical issues could enable an unauthenticated remote attacker to execute arbitrary code, posing a significant risk to internet-facing VPN infrastructure.
Check Point VPN solutions are fundamental for establishing secure connections between employees, remote offices, and corporate networks over the internet. Given their position at the network perimeter and often privileged access to internal resources, a successful compromise of these systems could provide attackers with a direct entry point into enterprise environments.
Technical Details of the Vulnerabilities
The first vulnerability, CVE-2026-85102, resides within the VPN negotiation process of Check Point Quantum Security Gateway devices. This flaw originates from insufficient validation of certificate trust data during the initial VPN connection setup. An external attacker can exploit this vulnerability without requiring valid credentials, effectively bypassing authentication mechanisms and executing arbitrary code on a vulnerable Security Gateway. This particular issue affects Security Gateway and Check Point Spark Firewall products when either Remote Access VPN or Site-to-Site VPN functionalities are enabled.
The second vulnerability, CVE-2026-85103, is a heap-based buffer overflow that occurs in the ASN.1 decoding flow for VPN certificates. ASN.1 is a widely used data format for digital certificates. A specially crafted certificate structure could trigger this memory corruption flaw, leading to remote code execution. Unlike the first vulnerability, CVE-2026-85103 can impact Check Point Security Management Server deployments in addition to Security Gateway and Spark Firewall products.
Expected Exploitation and Mitigation
The NCSC said that while it has not yet observed public exploit code for these vulnerabilities, it has assessed both the likelihood of exploitation and the potential impact as high. The agency anticipates that attackers will soon begin attempting widespread exploitation, elevating patching from routine maintenance to an immediate priority. A successful exploit could grant a threat actor full control over an exposed appliance, allowing access to or alteration of confidential information, lateral movement within connected networks, or disruption of business operations. A compromised VPN gateway is particularly valuable to attackers due to the trusted access it typically provides to internal systems.
Check Point released emergency updates on September 9, 2026. Supported deployments should install the latest Jumbo Hotfix Accumulator, specifically R82.10 Take 44 or later, R82 Take 126 or later, and R81.20 Take 166 or later. Additionally, Check Point LivePatch protection began rolling out on the same date for eligible systems.
What You Should Do
- Identify and Inventory: Locate all externally reachable Check Point VPN appliances within your environment.
- Verify Software Versions: Confirm the installed software release and current hotfix level for each appliance.
- Apply Updates Immediately: Deploy the appropriate emergency updates released by Check Point on September 9, 2026. This includes installing the latest Jumbo Hotfix Accumulator (R82.10 Take 44+, R82 Take 126+, R81.20 Take 166+).
- Enable LivePatch: Ensure Check Point LivePatch protection is enabled and updated for eligible systems.
- Restrict VPN Access (Site-to-Site): For Site-to-Site VPN environments, disable implied VPN rules and explicitly limit UDP port 500 and UDP port 4500 access only to known peer IP addresses. This measure reduces unnecessary exposure while patches are being validated and fully deployed.
- Monitor Logs: Review logs for any suspicious VPN negotiation or certificate-processing activity that could indicate attempted or successful exploitation.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.