“The NCSC assesses the likelihood of exploitation and the potential impact as high and expects exploitation attempts to occur soon,” the Dutch Nationaal Cyber Security Centrum warned, calling immediate attention to two critical Check Point VPN flaws tracked as CVE-2026-85102 and CVE-2026-85103.
The NCSC assessment and the immediate risk
The NCSC has issued a stark advisory: although no public proof-of-concept exploit has been reported, exploitation attempts are expected imminently. The agency rates both the likelihood of exploitation and the potential impact as high. Its guidance is unambiguous — organizations using Check Point VPN should install security updates “as soon as possible.” The NCSC also spelled out the potential consequences of successful exploitation: an attacker could take full control of a system, view or modify confidential data, and disrupt operations.
What the two CVEs actually do
Check Point’s advisories (sk1000117 and sk1000118), released on September 9, describe the technical faults behind the two tracked vulnerabilities. CVE-2026-85102 is an improper validation of certificate data during VPN negotiation that a remote attacker could exploit to execute arbitrary code on a Security Gateway. CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder that could allow remote code execution on Security Gateways and Security Management Servers. Both vulnerabilities permit remote actors to target VPN infrastructure during the certificate-handling phase of a VPN connection.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildAffected releases and the patch roadmap from Check Point
Check Point enumerated a broad set of affected releases. Impacted builds include R81.20, R82, R82.10, R81.10.x, and R82.00.x, as well as end-of-support versions R80 through R80.40, R81, and R81.10. Notably, Check Point has stated that R82.20 is not affected.
For mitigation, Check Point delivered fixes via Check Point LivePatch Take 24 for R81.20, R82, and R82.10. Additional fixes are included in these releases:
- R82.10 Jumbo Hotfix Accumulator Take 44 or later
- R82 Jumbo Hotfix Accumulator Take 126 or later
- R81.20 Jumbo Hotfix Accumulator Take 166 or later
- Spark R82.00.10 Build 2325 or later
- Spark R81.10.17 Build 4968 or later
Check Point’s timing: the fixes and advisories were issued on September 9. Administrators should verify that their deployed software matches the fixed takes or builds above or that the environment has received the LivePatch protection where applicable.
LivePatch protections and configuration caveats
Check Point community posts indicate that users of Check Point Live Patch (CPLP) should have received automatic protections for these flaws starting on September 9, and those mitigations may apply without a server reboot. However, CPLP protections are not universal: they are not available for versions other than R82.10, R82, and R81.20 and do not support all configurations. The NCSC and Check Point therefore both urge organizations to confirm whether their CPLP deployment actually provides coverage for their specific configuration and, where it does not, to apply the full security updates.
Mitigation advice for Site-to-Site VPN operators and immediate operational steps
Alongside patching, the NCSC offered a specific operational control for users of the ‘Site-to-Site VPN’ component: modify VPN rules to limit access to specific, trusted IP addresses. This targeted restriction reduces the attack surface for the certificate-processing vulnerabilities by constraining which external endpoints can initiate VPN negotiations. The NCSC’s dual message is clear — apply vendor fixes where available, and for Site-to-Site VPNs apply access restrictions until fixes are confirmed.
The record in this advisory is straightforward: two remote-code-execution vulnerabilities in widely deployed Check Point VPN components, vendor fixes dated September 9, and an authoritative warning from the Dutch NCSC that exploitation attempts are likely to begin soon. Network operators and administrators running affected Check Point releases should confirm their software version against the fixed takes and builds, verify CPLP protections where applicable, and apply rule-based access restrictions on Site-to-Site VPNs immediately.




