The Dutch National Cyber Security Center has raised alarm over two severe vulnerabilities in Check Point VPN products, warning that widespread exploitation is likely unless firms act immediately. Identified as CVE-2026-85102 and CVE-2026-85103, both flaws are rated 9.8 out of 10 for severity. They enable unauthenticated remote attackers to execute arbitrary code on internet-exposed VPN infrastructure.
What’s Vulnerable and How the Flaws Work
These issues impact several Check Point products: Security Gateway, Spark Firewall, and in some cases, the Security Management Server—whenever Remote Access VPN or Site-to-Site VPN features are enabled.
CVE-2026-85102 stems from improper validation of certificate trust during VPN negotiation. An attacker without credentials could bypass authentication and take control of a vulnerable gateway.
Meanwhile, CVE-2026-85103 arises from a heap-based buffer overflow in the ASN.1 certificate decoding routines. A malformed certificate could trigger memory corruption, permitting remote code execution across Security Gateway, Spark Firewall, and the Management Server.
Recommended Mitigations and Urgency
No public exploit code has yet been found, but NCSC assesses both the likelihood of attacks and their potential impact as high. Immediate patching is essential.
Check Point rolled out emergency fixes on September 9, 2026. Deployments should be updated using the latest Jumbo Hotfix Accumulators: R82.10 Take 44 or later, R82 Take 126+, or R81.20 Take 166+. Eligible systems can also apply LivePatch protections released the same day.
While patches are being applied, it’s advised to disable “implied VPN rules” and restrict access to UDP ports 500 and 4500 so that only known peer IPs can use them. Organizations should also audit their externally reachable Check Point VPN appliances, ensure correct hotfix levels, and monitor logs for anomalous negotiation or certificate activity.
This isn’t just another VPN patch notice. These flaws hit at a critical junction: tools that many companies use to secure remote access and site connections, sitting at the perimeter with high privileges. If exploited, they could give bad actors an open door into internal networks, data theft, or worse. What to watch next: proof-of-concept exploits, the timeline of patch adoption, and whether threat actors shift rapidly to weaponize these flaws. The window for mitigation is small—organizations using these Check Point VPN systems must treat this as urgent, not optional.