Dutch NCSC Warns of Imminent Exploitation Targeting Critical Check Point VPN Flaws CVE-2026-85102 and CVE-2026-85103

The Netherlands Nationaal Cyber Security Centrum (NCSC) has issued a high-priority security advisory alerting enterprise organizations to the imminent threat of active exploitation targeting two critical vulnerabilities in widely deployed Check Point Virtual Private Network (VPN) solutions. Tracked internationally as CVE-2026-85102 and CVE-2026-85103, these security defects pose a severe risk to corporate infrastructure, potentially allowing unauthorized threat actors to achieve remote code execution, bypass perimeter defenses, and acquire full systemic control over vulnerable gateways and management servers.
Although cybersecurity intelligence agencies and vendors have not yet observed widespread public deployment of a functional proof-of-concept (PoC) exploit code in the wild, the Dutch cybersecurity authority has raised its threat assessment to critical. Government officials emphasize that the combination of high impact and the complexity of the vulnerabilities makes imminent exploitation attempts nearly certain. Consequently, administrators across both public and private sectors are facing mounting pressure to deploy emergency security patches and apply immediate compensatory mitigations to safeguard sensitive internal corporate networks from compromise.
Understanding the Vulnerabilities: Technical Breakdown
Check Point VPN products serve as critical enterprise infrastructure components, establishing secure, encrypted tunnels that enable remote workforce personnel to connect safely to internal corporate systems and resources. Because these gateways sit squarely at the perimeter of corporate networks, any compromise of the VPN appliance itself can grant attackers a bridgehead deep into the enterprise environment.
The two vulnerabilities identified by Check Point and highlighted by the NCSC involve distinct yet equally dangerous code execution vectors within the VPN’s handling of network communications and cryptographic certificates:
-
CVE-2026-85102: This vulnerability stems from improper validation of certificate data during the initial VPN negotiation phase. If exploited, a remote attacker who is unauthenticated can send specially crafted certificate data to the target system. Because the gateway fails to properly validate this information, the malicious payload can trigger remote code execution directly on the Security Gateway.
-
CVE-2026-85103: This flaw is characterized as a heap overflow vulnerability residing within the VPN certificate ASN.1 (Abstract Syntax Notation One) decoder. ASN.1 is a standard notation used in telecommunications and computer networking to describe data structures for serialization, notably in cryptographic certificates. A flaw in how these structures are parsed can lead to memory corruption. By sending a malicious ASN.1 certificate structure during negotiation, an attacker can corrupt heap memory, ultimately resulting in remote code execution on both Security Gateways and Security Management Servers.
The successful exploitation of either vulnerability allows malicious actors to achieve complete system takeover. Once inside, threat actors can view, exfiltrate, or alter sensitive corporate data, deploy secondary payloads such as ransomware or persistent backdoors, and severely disrupt critical business operations on a global scale.
Chronology and Disclosure Timeline
The identification and patching of these vulnerabilities follow a coordinated disclosure timeline managed by Check Point Software Technologies, culminating in public awareness driven by national CERTs:
- September 9: Check Point officially acknowledges the vulnerabilities, publishing comprehensive security advisories designated as sk1000117 and sk1000118. Simultaneously, the vendor releases emergency software updates, security patches, and automated mitigations designed to neutralize the flaws before widespread malicious exploitation can begin.
- Mid-September: Security researchers and enterprise defense teams analyze the advisories, noting the absence of active in-the-wild exploitation at the time of release. However, threat intelligence indicators suggest that threat actors are actively reverse-engineering the patches to develop functional exploits.
- Late September: The Dutch Nationaal Cyber Security Centrum (NCSC) evaluates the threat landscape surrounding CVE-2026-85102 and CVE-2026-85103. Recognizing the high systemic risk posed by perimeter VPN vulnerabilities, the NCSC publishes an urgent advisory warning that active exploitation is imminent and urging immediate remediation actions.
Scope of Affected Products and Versions
The security flaws impact a broad range of enterprise software releases deployed across Check Point’s ecosystem. According to technical documentation supplied by the vendor, affected software branches and versions include:

- R81.20
- R82
- R82.10
- R81.10.x
- R82.00.x
- End-of-Support (EoS) versions: R80 through R80.40, R81, and R81.10
Conversely, Check Point has confirmed that version R82.20 of its VPN software is entirely unaffected by either CVE-2026-85102 or CVE-2026-85103, as the vulnerable code paths were either refactored or removed prior to this release. Organizations utilizing newer, fully updated environments or version R82.20 do not face the same immediate exposure, though security audits are still advised.
Remediation Options and Automated Mitigations
In response to the critical threat level, Check Point has made multiple remediation pathways available to system administrators, balancing the need for rapid deployment with the operational realities of enterprise IT management.
For modern deployments running versions R81.20, R82, and R82.10, Check Point has released Check Point LivePatch Take 24. A key feature of this remediation strategy is the Check Point Live Patch (CPLP) mechanism. According to discussions and notices published within official Check Point community forums, administrators utilizing CPLP should have automatically received protection against both vulnerabilities starting on September 9. Crucially, these LivePatches are designed to apply protections dynamically, eliminating the requirement to restart the underlying server hardware—a significant advantage for mission-critical enterprise environments that cannot afford scheduled downtime.
However, security teams must verify their specific configurations. The automatic CPLP mitigation is not universally available; it is restricted to versions R82.10, R82, and R81.20, and it does not support every possible custom configuration or legacy deployment architecture. Administrators are strongly advised to check their system logs and console status to confirm whether the automatic patches have been successfully applied.
Manual Mitigation and Compensatory Controls
For organizations running versions that do not support automated LivePatching, or for those requiring an immediate defense-in-depth posture while maintenance windows are scheduled, manual patching is mandatory. Administrators must apply the specific software updates associated with advisories sk1000117 and sk1000118 without delay.
In addition to software patches, the NCSC and security experts recommend implementing compensatory controls, particularly for organizations utilizing the Site-to-Site VPN component. System administrators should immediately review and modify their VPN access control lists and firewall rules. By strictly limiting inbound access to the VPN endpoints to specific, highly trusted external IP addresses or partner networks, organizations can drastically reduce their external attack surface, rendering it difficult for unauthenticated external attackers to initiate the malicious certificate negotiation process.
Broader Industry Implications and the Threat to Perimeter Infrastructure
The emergence of critical vulnerabilities in enterprise VPN appliances highlights a persistent and systemic challenge in modern cybersecurity: the vulnerability of perimeter defense hardware and software. Because VPN gateways serve as the primary gatekeepers to enterprise networks, they represent high-value targets for both advanced persistent threat (APT) groups and financially motivated cybercriminal syndicates.
In recent years, nation-state actors and cybercrime groups have increasingly shifted their focus from endpoint devices and internal software to edge infrastructure—including firewalls, load balancers, and VPN concentrators. Because these devices often operate with elevated privileges and are directly exposed to the public internet, a single unauthenticated remote code execution vulnerability can provide attackers with an immediate foothold inside a corporate network, completely bypassing perimeter firewalls and multi-factor authentication (MFA) controls designed to protect internal user endpoints.
The warning issued by the Dutch NCSC serves as a stark reminder that vulnerability disclosure does not give defenders an infinite window to react. While software vendors work swiftly to engineer patches, and automated delivery mechanisms like LivePatch aim to close the gap, the operational inertia of enterprise patch management frequently leaves systems exposed during the critical window between vulnerability disclosure and complete remediation.
As threat actors increasingly leverage automated scanners to identify and exploit unpatched edge devices within hours of a security advisory publication, the cybersecurity community continues to emphasize proactive asset management, rapid patch deployment, and strict network segmentation. For organizations relying on Check Point VPN solutions, the immediate implementation of LivePatches, official software updates, and IP-based access restrictions is no longer a routine maintenance task—it is an urgent operational necessity to prevent catastrophic enterprise compromise.






