The Dutch Nationaal Cyber Security Centrum (NCSC) has issued an urgent advisory regarding two critical remote code execution vulnerabilities in Check Point VPN gateways: CVE-2026-85102 and CVE-2026-85103. Although public proof-of-concept exploit code has not yet been publicly released, Dutch cyber authorities assess both the likelihood of active exploitation and the potential organizational impact as high, warning system administrators to expect exploitation attempts to begin imminently.
Enterprise VPN devices and perimeter security gateways remain primary targets for threat actors seeking initial access into internal networks. Because these systems process unauthenticated inbound connections directly at the network border, flaws in their handshake and certificate validation routines present adversaries with a direct route to bypass perimeter defenses and establish persistent operational footholds.
Understanding CVE-2026-85102 and CVE-2026-85103
Both security issues stem from severe implementation defects within how Check Point gateways decode and validate public key certificates during VPN session establishment.
The first flaw, CVE-2026-85102, involves improper validation of certificate data (classified under CWE-295) during VPN negotiation. An unauthenticated remote attacker can supply crafted certificate parameters to execute arbitrary code with elevated privileges on an exposed Security Gateway. The issue carries a CVSS v3.1 vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. This vector underscores an extreme exposure profile: the vulnerability is network-reachable (AV:N), low in attack complexity (AC:L), requires zero privileges or valid user accounts (PR:N), and executes without any user interaction (UI:N), leading to full compromise of device confidentiality, integrity, and availability.
The second flaw, CVE-2026-85103, is a heap-based buffer overflow in the VPN certificate’s Abstract Syntax Notation One (ASN.1) decoder. ASN.1 parsing is a standard cryptographic component used to handle structured certificate data during session initiation. By sending malformed ASN.1 certificate payloads during key exchange, an unauthenticated attacker can trigger memory corruption, enabling arbitrary code execution on both Security Gateways and centralized Security Management Servers.
Because certificate parsing occurs automatically prior to user authentication, adversaries can exploit both vulnerabilities remotely over the public internet without needing existing credentials or active user sessions.
Assessing Exploitation Risk and Blast Radius
The potential blast radius for an exploit targeting these vulnerabilities extends to complete administrative takeover of the affected perimeter infrastructure. Once an attacker achieves root-level remote code execution on a Check Point Security Gateway, they can manipulate routing, inspect or alter encrypted transit traffic, extract stored credentials, and pivot laterally into protected internal network segments. Furthermore, because CVE-2026-85103 affects central Security Management Servers, exploitation of a central management console could allow an attacker to compromise an organization’s entire fleet of managed firewalls.
Check Point released security advisories sk1000117 and sk1000118 addressing the flaws on September 9. The affected releases include:
- Supported Platforms: R81.20, R82, R82.10, R81.10.x, and R82.00.x.
- End-of-Support (EoS) Versions: R80, R80.10, R80.20, R80.30, R80.40, R81, and R81.10.
Systems running Check Point VPN version R82.20 are not affected by either flaw.
While automated scoring metrics such as EPSS measure the 30-day probability of exploitation for CVE-2026-85102 at 0.33% (placing it in the 25.9th percentile of scored vulnerabilities), security teams should prioritize government intelligence over static probability models. EPSS metrics reflect historical baseline trends; once national cyber defense bodies like the Dutch NCSC explicitly warn of imminent weaponization against perimeter appliances, immediate patch deployment becomes imperative.
Patching and Remediation Strategy
Organizations relying on affected Check Point infrastructure should execute the following remediation steps immediately:
- Apply Hotfixes and Updates: Upgrade supported gateways and management servers using Check Point LivePatch Take 24 for versions R81.20, R82, and R82.10, or apply the specific software updates listed in vendor advisories sk1000117 and sk1000118.
- Verify Live Patching Status: Administrators using Check Point Live Patch (CPLP) must manually confirm that automated protections issued since September 9 have successfully applied to target gateways. While CPLP protections apply without requiring a reboot, CPLP is limited to versions R81.20, R82, and R82.10 and does not cover every custom deployment configuration.
- Decommission or Upgrade EoS Systems: Environments running legacy End-of-Support releases (R80 through R81.10) must upgrade to supported releases such as R82.20 immediately, as EoS installations will not receive security fixes.
- Restrict Access to Site-to-Site VPNs: For organizations using the Site-to-Site VPN feature, modify gateway security rules to restrict incoming VPN negotiation traffic exclusively to trusted, explicit remote IP addresses, mitigating unauthenticated scanning and exploit delivery.
Related content
Check Point Fixes Critical Pre-Auth Root RCE in Security Management Servers
Security NewsTechnical Details, PoC Published for Exploited Check Point Vulnerability (CVE-2026-16232)
Security NewsCheck Point Patches Zero-Day Vulnerability CVE-2026-16232 Under Active Exploitation
AdvisoryCheck Point SmartConsole Flaw Exposes Admin Tokens to Remote Attackers
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call