AIO APEX

Check Point patches two CVSS 9.8 VPN flaws as Dutch cyber agency warns exploitation is imminent

BleepingComputer
Share:
Check Point patches two CVSS 9.8 VPN flaws as Dutch cyber agency warns exploitation is imminent

The Netherlands' National Cyber Security Centre (NCSC) issued an urgent advisory on September 12, warning organizations that two critical remote-code-execution vulnerabilities in Check Point's VPN products face imminent exploitation — despite the absence of any public proof-of-concept exploit.

Both flaws, tracked as CVE-2026-85102 and CVE-2026-85103, carry a CVSS score of 9.8 — the top end of the severity scale — and require no authentication to exploit. An attacker on the internet could send a specially crafted certificate packet to a Check Point Security Gateway and gain full system control without ever logging in.

What the vulnerabilities do

CVE-2026-85102 is an improper validation bug in the certificate-handling code used during VPN session negotiation. An unauthenticated remote attacker can trigger arbitrary code execution on the Security Gateway by sending a malformed certificate during the handshake phase.

CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder. This one is broader in impact: it affects not only Security Gateways but also Security Management Servers, meaning an attacker could potentially compromise the management plane that controls all VPN policy.

Check Point published patches on September 9 via security advisories sk1000117 and sk1000118. The Dutch NCSC issued its warning three days later after assessing that exploitation attempts are likely in the near term, even though no exploit code has yet appeared in public.

Which systems are affected

The vulnerabilities affect Check Point Quantum Security Gateway and Security Management products running the following software versions: R81.20, R82, R82.10, R81.10.x, and R82.00.x. End-of-support versions R80 through R80.40, R81, and R81.10 are also vulnerable and may never receive official patches.

Organizations running R82.20 are not affected.

What to do right now

Check Point recommends installing LivePatch Take 24 for users on R81.20, R82, and R82.10. For R82.10 specifically, the Jumbo Hotfix Accumulator Take 44 or later is required; R82 users need Take 126 or later; R81.20 users need Take 166 or later.

Organizations using Site-to-Site VPN that cannot patch immediately should restrict VPN access to trusted IP addresses as a temporary mitigation — though this is not a substitute for patching.

For organizations still running end-of-support versions, the advice is straightforward: upgrade to a supported release. Running unpatched, internet-exposed VPN gateways on end-of-life software makes exploitation straightforward once a working exploit appears.

Why the Dutch NCSC warning matters

Government cyber agencies rarely use the word “imminent” unless they have threat intelligence suggesting active adversary interest. The Dutch NCSC's assessment that “exploitation is expected soon” likely reflects monitored activity — scanning, reconnaissance, or closed-community circulation of exploit techniques — that hasn’t yet crossed into public disclosure.

Check Point VPNs are high-value targets for nation-state actors and ransomware groups precisely because they sit at the edge of enterprise networks. Compromising a VPN gateway gives attackers a foothold inside the corporate network without triggering typical endpoint detection. The pre-authentication nature of both flaws makes mass-exploitation feasible: no credential spray, no phishing, just a network packet.

As first reported by BleepingComputer, this advisory arrives in a busy month for VPN and perimeter security, following patches for Cisco’s Firewall Management Center and several other network appliances. Security teams should treat this as an emergency change, not a routine monthly patch cycle.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share: