LIVE · cybersecurity feed
Live wire
CVE-2026-85102critical

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]

zeroday.news ·

Photo: Anass Sedrati (CC BY-SA 4.0) via Wikimedia Commons

The Dutch Nationaal Cyber Security Centrum (NCSC) has issued a warning regarding the imminent exploitation of two critical vulnerabilities in Check Point VPN products, identified as CVE-2026-85102 and CVE-2026-85103. The agency has assessed the likelihood of exploitation and the potential impact as high, urging organizations to apply security updates promptly.

Check Point, an enterprise VPN solution provider, released fixes for these vulnerabilities on September 9, accompanied by security advisories sk1000117 and sk1000118. While no public proof-of-concept exploits have been reported, the NCSC anticipates exploitation attempts will begin soon.

CVE-2026-85102 is described as an improper validation of certificate data during the VPN negotiation process. This flaw could allow a remote attacker to execute arbitrary code on a Security Gateway. CVE-2026-85103 is a heap overflow vulnerability found in the VPN certificate ASN.1 decoder, which could also lead to remote code execution on both Security Gateways and Security Management Servers.

The affected Check Point releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x. Additionally, end-of-support (EoS) versions such as R80 through R80.40, R81, and R81.10 are also vulnerable. Check Point VPN version R82.20 is confirmed not to be affected by either flaw.

Patches for these vulnerabilities are included in Check Point LivePatch Take 24 for R81.20, R82, and R82.10. Further fixes are integrated into specific Jumbo Hotfix Accumulator versions: R82.10 Jumbo Hotfix Accumulator Take 44 or later, R82 Jumbo Hotfix Accumulator Take 126 or later, and R81.20 Jumbo Hotfix Accumulator Take 166 or later. Additionally, Spark R82.00.10 Build 2325 or later and Spark R81.10.17 Build 4968 or later also contain the necessary remediations.

The NCSC has highlighted that successful exploitation of these flaws could grant an attacker full control over a system, enable access to or modification of confidential data, and disrupt operations. System administrators are strongly advised to apply the security updates as quickly as possible.

For organizations utilizing the Site-to-Site VPN component, the NCSC recommends an additional measure: modifying VPN rules to restrict access to only specific, trusted IP addresses.

According to information shared in Check Point's community forums, users of Check Point Live Patch (CPLP) should have received all available protections for these two vulnerabilities since September 9. These fixes are designed to apply automatically, often without requiring a server reboot. However, CPLP users are advised to verify that these automatic mitigations have been successfully applied, as they are not available for all configurations or for versions other than R82.10, R82, and R81.20.

vulnerabilities in this storyCVE-2026-85102CVE-2026-85103
vulnerabilitynation-statecloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

vulnerabilitycritical

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice