THE Dutch National Cyber Security Centre (NCSC) has warned of two critical vulnerabilities in Check Point VPN products, both rated 9.8 on the CVSS scale. CVE‑2026‑85102 affects the VPN negotiation process and could allow an unauthenticated attacker to bypass security checks and execute code on a gateway. CVE‑2026‑85103 is a heap overflow in the certificate ASN.1 decoder that can also lead to remote code execution on Security Gateways and Security Management Servers.
The NCSC rates both the likelihood of exploitation and potential damage as high, and expects exploitation attempts soon. However, the article says no public proof of concept has emerged and does not confirm active exploitation.
Check Point issued advisories sk1000117 and sk1000118 on 9 September. Affected releases include R81.20, R82, R82.10, R81.10.x and R82.00.x, as well as end-of-support versions from R80 through R81.10; R82.20 is not affected. Fixes are available through LivePatch Take 24 or version-specific Jumbo Hotfix updates. LivePatch users on R81.20, R82 or R82.10 may already be protected without a reboot, but should verify their configuration because coverage varies. The NCSC advises installing the updates as soon as possible.
Organisations using Site-to-Site VPN should also disable implied rules and restrict VPN access to specific trusted IP addresses. Those unsure of their version or remediation status should contact their IT provider.