The Nationaal Cyber Security Centrum (NCSC) of the Netherlands has issued a warning regarding two critical vulnerabilities affecting Check Point VPN, identified as CVE-2026-85102 and CVE-2026-85103. Despite the absence of any disclosed public exploit code, the agency is pressing organizations to deploy security updates addressing these issues immediately.
"The NCSC assesses the likelihood of exploitation and the potential impact as high and expects exploitation attempts to occur soon," the NCSC warns.
Check Point VPN serves as an enterprise-grade platform enabling remote staff to establish secure, encrypted connections to their organization's internal systems.
On September 9, Check Point released patches for both vulnerabilities alongside corresponding security advisories designated sk1000117 and sk1000118.
Vulnerability Details
CVE-2026-85102 involves inadequate validation of certificate information during the VPN handshake process, which an unauthenticated remote attacker could leverage to run arbitrary code on a Security Gateway.
CVE-2026-85103 describes a heap buffer overflow within the VPN certificate ASN.1 parsing component, potentially enabling remote code execution on both Security Gateways and Security Management Servers.
The vulnerabilities impact R81.20, R82, R82.10, R81.10.x, and R82.00.x releases. Additionally, end-of-support versions R80 through R80.40, R81, and R81.10 are also vulnerable.
Available Fixes
Check Point LivePatch Take 24 resolves both issues for R81.20, R82, and R82.10 deployments. Remediation is also available through the following updates:
- R82.10 Jumbo Hotfix Accumulator Take 44 or later
- R82 Jumbo Hotfix Accumulator Take 126 or later
- R81.20 Jumbo Hotfix Accumulator Take 166 or later
- Spark R82.00.10 Build 2325 or later
- Spark R81.10.17 Build 4968 or later
Check Point VPN version R82.20 is unaffected by either vulnerability.
Potential Impact and Mitigation
The NCSC has cautioned that successful exploitation could grant attackers complete system control, unauthorized access to sensitive information, and the ability to interrupt normal operations.
System administrators are strongly advised to implement security updates at the earliest opportunity. For organizations utilizing the 'Site-to-Site VPN' functionality, the recommendation is to adjust VPN policies to restrict connections to designated, pre-approved IP ranges.
According to communications in Check Point's community forums, subscribers to Check Point Live Patch (CPLP) have had access to protections against both vulnerabilities since September 9, with these mitigations applying automatically without requiring server restarts.
CPLP subscribers should verify their protection status through this automatic safeguard, keeping in mind that this capability is restricted to R82.10, R82, and R81.20 versions and does not cover all deployment scenarios.
Source: BleepingComputer