Check Point has patched two critical vulnerabilities in its VPN products, and the Dutch national cyber
security centre (NCSC) warns that exploitation is imminent. CVE-2026-85102 is an improper validation
of certificate data during VPN negotiation that a remote attacker could use to run code on a Security
Gateway (Check Point’s advisory also describes an authentication bypass affecting Remote Access
and Site-to-Site VPN), and CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder
that allows remote code execution on Security Gateways and Security Management Servers. Both
were fixed on 9 September 2026. The NCSC assesses the likelihood of exploitation and the potential
impact as high, noting that a successful attack could give an adversary full control of a system, expose
or alter confidential data, and disrupt operations, even though no public proof-of-concept exists yet.
Because Check Point VPN gateways sit at the network edge, every affected organisation should apply
the fixes immediately and restrict VPN exposure.
1. Vulnerability Details
CVE ID – CVE-2026-85102, CVE-2026-85103
EXPLOIT STATUS -Fixed by Check Point on 9 Sep 2026 (advisories sk1000117 and sk1000118). The Dutch
NCSC assesses likelihood and impact as high and expects exploitation attempts soon; no
public proof-of-concept has been reported. Not in CISA KEV at time of writing.
Check Point disclosed two independently critical remote code execution flaws in its VPN products. Both involve how the
VPN handles certificate data during negotiation, and either can lead to code execution on internet-facing Check Point
infrastructure.
- CVE-2026-85102: (Critical) Improper validation of certificate data during VPN negotiation, which a remote attacker could exploit to execute arbitrary code on a Security Gateway. Check Point’s advisory (sk1000117) describes it as an authentication bypass and remote code execution affecting Remote Access and Site-to-Site VPN.
- CVE-2026-85103: (Critical) A heap overflow in the VPN certificate ASN.1 decoder (sk1000118) that could allow remote code execution on both Security Gateways and Security Management Servers.
2. Affected Products
- Affected: Check Point R81.20, R82, R82.10, R81.10.x and R82.00.x, plus the end-of-support versions R80 through R80.40, R81 and R81.10. R82.20 is not affected by either flaw.
- Fixed via Check Point LivePatch Take 24 for R81.20, R82 and R82.10, and in: R82.10 Jumbo Hotfix Accumulator Take 44 or later, R82 Jumbo Hotfix Accumulator Take 126 or later, R81.20 Jumbo Hotfix Accumulator Take 166 or later, Spark R82.00.10 Build 2325 or later, and Spark R81.10.17 Build 4968 or later.
3. Exploitation Status
A fix is available and a national CERT has warned that exploitation is expected soon.
- NCSC assessment: The Dutch NCSC rates the likelihood of exploitation and the potential impact as high and expects exploitation attempts to occur soon. Successful exploitation could allow an attacker to take full control of a system, view or modify confidential data, and disrupt operations. No public proof-of-concept has been reported.
- Automatic mitigation (CPLP): Check Point Live Patch users on R82.10, R82 and R81.20 should have received protections automatically since 9 September 2026, applying without a server reboot. CPLP is not available for other versions and does not support all configurations, so coverage must be confirmed, not assumed.
4. Recommendations
- Patch immediately: apply Check Point’s fixes for CVE-2026-85102 and CVE-2026-85103, using LivePatch Take 24 (R81.20/R82/R82.10) or the relevant Jumbo Hotfix Accumulator (R82.10 Take 44+, R82 Take 126+, R81.20 Take 166+) and Spark builds (R82.00.10 Build 2325+, R81.10.17 Build 4968+). Prioritise internet facing gateways.
- Upgrade end-of-support versions: R80 through R80.40, R81 and R81.10 are affected and out of support, so migrate to a fixed, supported release (R82.20 is not affected by either flaw).
- Confirm CPLP coverage: if you use Check Point Live Patch on R82.10, R82 or R81.20, verify the automatic protections applied since 9 September, and do not assume coverage, as CPLP is unavailable for other versions and some configurations.
- Reduce exposure: for Site-to-Site VPN, restrict VPN rules to specific trusted IP addresses, and limit and monitor external access to Remote Access VPN and management interfaces.
- Given the NCSC’s imminent-exploitation warning, monitor gateway and VPN logs for anomalous certificate negotiation failures, unexpected crashes and signs of code execution, and review internet-facing gateways and management servers for compromise as a priority.
5. Sources
- https://www.ncsc.nl/alerts/kritieke-kwetsbaarheden-in-check-point-vpn-producten-met-actief
misbruik-verwacht-update-nu - https://support.checkpoint.com/results/sk/sk1000117/
- https://support.checkpoint.com/results/sk/sk1000118/
- https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-ex
ploitation-is-imminent/
Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn
No related posts found.