Critical Check Point VPN Flaws Pose Imminent Threat to Businesses
A warning has been issued by the Dutch Nationaal Cyber Security Centrum (NCSC) that two critical vulnerabilities in Check Point’s Virtual Private Network (VPN) solution are about to be exploited. The flaws, tracked as CVE-2026-85102 and CVE-2026-85103, have already prompted Check Point to release patches, but the NCSC advises that organizations must act swiftly to prevent potential attacks.
Check Point VPN is a widely used enterprise solution that enables remote employees to securely connect to their company’s internal network via encrypted connections. The two vulnerabilities allow an attacker to execute arbitrary code on a Security Gateway or Security Management Server, potentially giving them full control of the system and access to confidential data.
The flaws are not new; Check Point released fixes for CVE-2026-85102 and CVE-2026-85103 on September 9, along with separate security advisories. However, the NCSC believes that exploitation attempts will occur soon due to the high likelihood of attack and potential impact. The agency has urged organizations to install the patches as soon as possible to prevent potential disruptions.
The affected releases include several versions of Check Point VPN, including R81.20, R82, R82.10, R81.10.x, and R82.00.x, as well as end-of-support (EoS) versions R80 through R80.40, R81, and R81.10. The patches are available for download from Check Point’s website and can be applied manually or automatically through the company’s LivePatch feature.
In addition to patching their VPN solutions, organizations using the ‘Site-to-Site VPN’ component are advised to modify their VPN rules to limit access to specific, trusted IP addresses. This will help prevent an attacker from gaining unauthorized access to sensitive data and systems.
It is essential for system administrators to take immediate action to protect their organizations from these critical vulnerabilities. Failure to do so could result in significant disruptions to operations, including data breaches and unauthorized access to confidential information. The NCSC’s warning highlights the importance of staying up-to-date with security patches and taking proactive measures to prevent potential attacks.
For those using Check Point Live Patch (CPLP), it is recommended to check if they are protected by the automatic mitigation since September 9. However, this feature only supports specific versions and configurations, so organizations should not rely solely on CPLP for protection.
Source: Bleeping Computer — 2026-09-12