The Dutch National Cyber Security Centre (NCSC) warned that exploitation of two critical vulnerabilities in the Check Point VPN solution could begin soon, urging organizations to install the security updates as quickly as possible. No publicly available proof of concept (PoC) has been published so far, but the center’s assessment of the likelihood and impact of exploitation was high.
Two vulnerabilities that could lead to remote code execution
The first vulnerability is identified as CVE-2026-85102 and is related to improper validation of certificate data during VPN connection negotiation. A remote attacker could exploit it to execute arbitrary code on a Security Gateway.
CVE-2026-85103 concerns a heap overflow in the VPN certificate parser for ASN.1 structures, and could also enable remote code execution on Security Gateways and Security Management Servers.
According to the NCSC, exploiting the two vulnerabilities could lead to complete system takeover, the reading or modification of confidential data, and disruption of operations.
Affected versions and fixes
Check Point issued its fixes on September 9, alongside two security advisories identified as sk1000117 and sk1000118. The affected versions include R81.20, R82, R82.10, R81.10.x, and R82.00.x, in addition to versions that have reached end of support: R80 through R80.40, R81, and R81.10.
The fixes are available through Check Point LivePatch Take 24 for versions R81.20, R82, and R82.10, and have also been included in the following versions or later:
- R82.10 Jumbo Hotfix Accumulator Take 44
- R82 Jumbo Hotfix Accumulator Take 126
- R81.20 Jumbo Hotfix Accumulator Take 166
- Spark R82.00.10 Build 2325
- Spark R81.10.17 Build 4968
Check Point explained that version R82.20 is not affected by the two vulnerabilities.
What should system administrators do?
The NCSC’s main recommendation is to apply the security updates immediately. For organizations using the Site-to-Site VPN component, the agency recommends modifying VPN rules so that access is limited to specific, trusted IP addresses.
Users of Check Point Live Patch should have received the available protection since September 9, even without restarting the server. However, the actual protection status should be verified, because the automatic mitigation mechanism is not available outside R82.10, R82, and R81.20, and it does not support all configurations.
Why does this warning matter?
The warning is significant because the two vulnerabilities are located in VPN components that handle connections and certificates, and potential exploitation is not limited to exposing restricted information but could extend to code execution and control of enterprise systems. Since the NCSC expects exploitation attempts soon, the absence of a public PoC does not eliminate the priority of patching. The practical verification point for each organization remains identifying the exact version in use, confirming that LivePatch covers its configuration, or installing the appropriate fix instead of assuming that automatic mitigation is sufficient.