The Dutch Nationaal Cyber Security Centrum (NCSC) has issued a warning that exploitation of two critical Check Point VPN vulnerabilities is imminent, urging organizations to patch immediately even though no public proof-of-concept exploit has surfaced yet.
The flaws, tracked as CVE-2026-85102 and CVE-2026-85103, carry a CVSS score of 9.8 and can be exploited without authentication to achieve remote code execution. Check Point disclosed and patched both issues on September 9.
What the flaws do
CVE-2026-85102 stems from improper validation of certificate data during VPN negotiation and affects Security Gateway and Check Point Spark Firewall products using Site-to-Site or Remote Access VPN. CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder, impacting Security Gateway, Spark Firewall, and Security Management Server deployments.
Check Point says it discovered both vulnerabilities internally and has seen no evidence of in-the-wild exploitation so far. The NCSC nonetheless assesses both the likelihood of exploitation and potential impact as high, warning that successful attacks could let an intruder take full control of affected systems, access or alter confidential data, and disrupt operations.
Affected versions and fixes
Impacted releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, as well as end-of-support versions R80 through R80.40, R81, and R81.10. Version R82.20 is not affected.
Patches are delivered via Check Point LivePatch Take 24 for R81.20, R82, and R82.10, or through updated Jumbo Hotfix Accumulators: Take 44 or later for R82.10, Take 126 or later for R82, and Take 166 or later for R81.20. Spark firewall users need R82.00.10 Build 2325 or R81.10.17 Build 4968 or later.
Mitigations
Organizations using LivePatch should already have automatic protections applied since September 9, without requiring a reboot, though this coverage is limited to R82.10, R82, and R81.20 and does not support every configuration. Check Point recommends that Site-to-Site VPN users disable implied VPN rules and manually restrict access for UDP/500 and UDP/4500 to specific, trusted peer IP addresses. Locally managed Spark Firewall instances are not covered by the automatic mitigation and should be updated with the latest Jumbo hotfixes as soon as possible.
Given the NCSC’s assessment and the ease of exploitation once a working exploit emerges, security teams should treat patching as urgent and verify LivePatch protection status where applicable.
