TechNewsReel
Live

Dutch NCSC Warns of Critical RCE Flaws in Check Point VPN Products

Two vulnerabilities rated 9.8 on the CVSS scale allow unauthenticated attackers to execute remote code.

TechNewsReel Newsroom · September 12, 2026

The Dutch National Cyber Security Centrum (NCSC) has issued an urgent warning regarding two critical vulnerabilities in Check Point VPN products that could allow unauthenticated remote code execution. Security experts warn that exploitation of these flaws is imminent, prompting an immediate call for organizations to apply available security updates.

Both vulnerabilities, identified as CVE-2026-85102 and CVE-2026-85103, carry a severe CVSS score of 9.8. According to the NCSC and security advisories, CVE-2026-85102 is an authentication-bypass and validation flaw occurring during the VPN connection setup process. Meanwhile, CVE-2026-85103 involves a heap overflow within the ASN.1 decoding process for VPN certificates. This second flaw specifically enables remote code execution (RCE) on both Security Management systems and Security Gateways.

Affected Systems and Scope

The vulnerabilities impact a wide range of Check Point software versions, specifically R82.10 (Jumbo Hotfix Take 43 or below), R82 (Take 125 or below), and R81.20 (Take 165 or below). The risk is amplified by the fact that these flaws affect both Site-to-Site VPN and Remote Access VPN functionalities. Because these services are designed to provide secure perimeter access, they are often exposed directly to the public internet, increasing the attack surface for potential threats.

Industry Implications

The severity of these flaws stems from the ability of an unauthenticated attacker to execute arbitrary code remotely. As VPNs serve as the primary gateway into corporate networks, a successful breach could grant an attacker an initial foothold for lateral movement across an organization's internal infrastructure. This level of access typically leads to full network compromise, the theft of sensitive corporate data, and the deployment of ransomware.

Mitigation and Next Steps

Check Point has released security updates to address both vulnerabilities. For organizations utilizing Check Point Live Patch, automatic protection was deployed starting September 9, 2026. Administrators not using the automated service are urged to manually verify their software versions and apply the necessary Jumbo Hotfixes immediately. Security teams should monitor for unusual activity on their gateways as the industry awaits reports of active exploitation in the wild.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.