Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Dutch NCSC warns exploitation of two critical Check Point VPN flaws is imminent

The Dutch Nationaal Cyber Security Centrum (NCSC) warns that exploitation of two critical flaws in Check Point VPN is imminent. The vulnerabilities are tracked as CVE-2026-85102 and CVE-2026-85103. No public proof-of-concept exploit has been reported, but the agency expects exploitation attempts soon and assesses both likelihood and potential impact as high.

Check Point issued fixes on September 9, with advisories sk1000117 and sk1000118. CVE-2026-85102 involves improper certificate-data validation during VPN negotiation and could let a remote attacker execute arbitrary code on a Security Gateway. CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder that could enable remote code execution on Security Gateways and Security Management Servers.

  • Affected releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, plus end-of-support versions R80 through R80.40, R81, and R81.10.
  • Check Point LivePatch Take 24 fixes both flaws for R81.20, R82, and R82.10. Check Point VPN version R82.20 is not affected.
  • Administrators should apply the updates. Site-to-Site VPN users should limit rules to specific trusted IP addresses.

Check Point Live Patch (CPLP) users should have received protections since September 9 without a server reboot, but the mitigation is limited to R82.10, R82, and R81.20 and does not support all configurations.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.