The Dutch National Cyber Security Center (NCSC) has issued an urgent advisory regarding two major vulnerabilities identified in Check Point VPN products. These flaws pose a significant threat, with projections of imminent widespread exploitation.
Critical Vulnerabilities Identified
Organizations utilizing Check Point’s security gateways, management systems, or Spark Firewall products are advised to promptly implement the recommended patches. The vulnerabilities, tracked as CVE-2026-85102 and CVE-2026-85103, each have a critical CVSS severity rating of 9.8, indicating their potential to allow unauthorized remote attackers to execute arbitrary code, thus compromising the security of VPN infrastructures exposed to the internet.
Impact on Network Security
Check Point’s VPN solutions are integral to securely connecting employees, offices, and networks over the internet. Positioned at the network’s perimeter, these systems often possess elevated access to internal resources. Any successful breach could potentially grant attackers entry into corporate environments, posing severe security risks.
The vulnerability CVE-2026-85102 impacts the VPN negotiation process within Check Point Quantum Security Gateway devices due to inadequate validation of certificate trust data during connection setup. This flaw enables attackers, without valid credentials, to bypass authentication and execute arbitrary code on susceptible gateways.
Patching and Mitigation Measures
The second vulnerability, CVE-2026-85103, involves a heap-based buffer overflow in the ASN.1 decoding process for VPN certificates. ASN.1 is a format widely used in digital certificates. Exploiting a specially crafted certificate structure can lead to memory corruption and remote code execution, affecting not only Security Gateway and Spark Firewall products but also Security Management Server deployments.
Despite the absence of public exploit code, the NCSC assesses the likelihood of exploitation as high. Therefore, prioritizing patch deployment over routine maintenance is crucial. Successful exploitation could enable attackers to control exposed appliances, access or modify confidential data, infiltrate connected networks, or disrupt operations.
Check Point released critical updates on September 9, 2026. Organizations are urged to install the latest Jumbo Hotfix Accumulator updates, which include R82.10 Take 44 or later, R82 Take 126 or later, and R81.20 Take 166 or later. LivePatch protection for eligible systems has also been rolled out.
For Site-to-Site VPN configurations, administrators should disable implied VPN rules and restrict UDP port 500 and UDP port 4500 access to verified peer IP addresses. This measure minimizes exposure risks while patches are being applied.
Organizations should audit all externally accessible Check Point VPN appliances, verify the software release and hotfix status, deploy necessary updates, and scrutinize logs for unusual VPN negotiation or certificate-processing activities.
