The Dutch Nationaal Cyber Security Centrum (NCSC) is warning that exploitation of two Check Point VPN flaws is imminent, urging organisations to apply available patches without delay. The two vulnerabilities, tracked as CVE-2026-85102 and CVE-2026-85103, have each been assigned a CVSS score of 9.8, placing them firmly in the critical severity category, according to Computing.
No public proof-of-concept (PoC) exploit has been reported at this stage, but the NCSC is not waiting for one to appear before sounding the alarm. ‘The NCSC assesses the likelihood of exploitation and the potential impact as high and expects exploitation attempts to occur soon,’ the agency states in its advisory.
What the two Check Point VPN flaws actually do
The vulnerabilities sit within the VPN negotiation and certificate processing components of Check Point‘s Security Gateway products. CVE-2026-85102 is an improper validation of certificate data during VPN negotiation, a flaw that a remote attacker could exploit to execute arbitrary code on a Security Gateway without any authentication. CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder (an equally ugly class of bug) that could allow remote code execution on both Security Gateways and Security Management Servers.
Taken together, the NCSC warns that successful exploitation could let an attacker take full control of an affected system, view or modify confidential data, and disrupt operations. With scores of 9.8 on the CVSS scale, these are not flaws to sit on.
Affected versions and the patch picture for Check Point VPN flaws
The affected releases span a broad swathe of current and legacy Check Point software: R81.20, R82, R82.10, R81.10.x, and R82.00.x are all in scope, as are the end-of-support (EoS) versions R80 through R80.40, R81, and R81.10. Check Point R82.20 is not affected by either flaw.
Check Point issued fixes for both vulnerabilities on 9 September, accompanied by separate security advisories (sk1000117 and sk1000118). The primary fix for users on supported current releases is Check Point LivePatch Take 24, available for R81.20, R82, and R82.10. For those who prefer or require a full hotfix accumulator, the following builds also contain the fix:
R82.10 Jumbo Hotfix Accumulator Take 44 or later; R82 Jumbo Hotfix Accumulator Take 126 or later; R81.20 Jumbo Hotfix Accumulator Take 166 or later; Spark R82.00.10 Build 2325 or later; Spark R81.10.17 Build 4968 or later.
Users of Check Point Live Patch (CPLP) should, according to a post in Check Point’s community forums, have received all available protections for both flaws automatically since 9 September, with fixes applying even without a server reboot. That is the good news. The caveat: CPLP automatic mitigation is only available for R82.10, R82, and R81.20, and does not support all configurations. Administrators should verify that automatic protection has actually landed rather than assuming it has.
For those running the ‘Site-to-Site VPN’ component, the NCSC adds a further layer of advice: modify VPN rules to restrict access to specific, trusted IP addresses, buying time against exploitation even if a full patch has not yet been applied.
The NCSC’s message to system administrators is blunt: apply the security updates as soon as possible. With a CVSS 9.8 rating on both Check Point VPN flaws and no reboot required for LivePatch users, the calculus for delaying is not a favourable one. Administrators on EoS versions face a harder path, as LivePatch coverage does not extend to those releases, making an upgrade or migration conversation hard to defer any longer.

