Check Point VPN flaws: Dutch NCSC says exploitation is imminent
The Dutch NCSC expects two critical Check Point VPN flaws to be exploited shortly, even though no public attack code has been reported. Patches have been available since 9 September 2026.

On 12 September 2026, the Dutch Nationaal Cyber Security Centrum (NCSC) issued a warning about two critical vulnerabilities in Check Point VPNs, tracked as CVE-2026-85102 and CVE-2026-85103. The agency is not reporting attacks it has seen — it is reporting the ones it expects. It rates both the likelihood of exploitation and the potential impact as high, and expects attempts in the near term. No public exploit code has surfaced at this stage, according to Bleeping Computer, which relayed the advisory the same day.
Two flaws, one weak spot: the certificate
Both vulnerabilities sit in how certificates are handled during VPN negotiation.
CVE-2026-85102 is improper validation of certificate data during that negotiation. A remote attacker can use it to run arbitrary code on a Security Gateway.
CVE-2026-85103 is a heap overflow in the ASN.1 decoder for VPN certificates. Its blast radius is wider: it allows remote code execution on Security Gateways, but also on Security Management Servers — the machine your security policy is administered from.
The NCSC spells out what successful exploitation could mean: full takeover of a system, access to or modification of confidential data, disruption of operations. Remember what this kit is for: remote access for staff working from home. It sits on the public internet by design, porch light on, address published.
Which versions are affected
The affected branches are R81.20, R82, R82.10, R81.10.x and R82.00.x. Add to those a set of end-of-life versions — R80 through R80.40, R81 and R81.10 — where the question isn’t which hotfix to apply, but when the migration is scheduled.
One detail worth checking before you write off your evening: R82.20 is affected by neither flaw.
What you actually need to install
Check Point shipped its fixes on 9 September 2026, alongside two separate security advisories, sk1000117 and sk1000118.
Both flaws are fixed by LivePatch Take 24 for R81.20, R82 and R82.10. The fixes are also rolled into the following packages: Jumbo Hotfix Accumulator Take 44 or later for R82.10, Take 126 or later for R82, Take 166 or later for R81.20, plus Spark R82.00.10 build 2325 or later and Spark R81.10.17 build 4968 or later.
Those numbers are the first thing to line up against what you’re already running, before anything else. The list of vulnerable versions and the list of fixed takes do not map onto each other in any obvious way.
Automatic patching doesn’t cover everyone
According to a post on Check Point’s community forums, Check Point Live Patch (CPLP) users have received every protection available for both flaws since 9 September, and those fixes apply without rebooting the server.
The caveat matters: that automatic mitigation is only offered for R82.10, R82 and R81.20, and it does not support every configuration. Being a CPLP customer is not a clean bill of health — open the console and confirm the protection actually landed on your gateway.
Finally, for deployments using the Site-to-Site VPN component, the NCSC recommends changing your VPN rules to restrict access to specific IP addresses you consider trusted. That shrinks the attack surface; it is not a substitute for the patch.
The NCSC isn’t announcing a breach in progress. It’s announcing the one that hasn’t started yet — and that gap is the only window in which a patch is still a line in next week’s change calendar, rather than a phone call at three in the morning.
Sources (1)
- Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentbleepingcomputer.com
Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.


