Critical Flaws in Check Point VPN Leave Systems Vulnerable to Attack
A warning from the Dutch Nationaal Cyber Security Centrum (NCSC) has sent shockwaves through the cybersecurity community, as two critical flaws in Check Point’s Virtual Private Network (VPN) solution are poised for imminent exploitation. The agency is urging organizations to install security updates addressing these issues as soon as possible, as the consequences of a successful attack could be catastrophic.
Check Point VPN is an enterprise-grade solution designed to allow remote employees to securely connect to their company’s internal network via encrypted connections. However, two critical vulnerabilities – tracked as CVE-2026-85102 and CVE-2026-85103 – have been identified in the software. These flaws can be exploited by a remote attacker to execute arbitrary code on a Security Gateway or Security Management Server, potentially allowing them to take full control of a system, access confidential data, or disrupt operations.
The NCSC assesses the likelihood of exploitation and potential impact as high, warning that exploitation attempts are expected to occur soon. To mitigate this risk, Check Point has released fixes for the flaws in its latest security advisories (sk1000117 and sk1000118). The affected releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, as well as end-of-support versions R80 through R80.40, R81, and R81.10.
Fortunately, fixes are available for these vulnerabilities, and Check Point has provided detailed instructions on how to apply them. For those using the ‘Site-to-Site VPN’ component, modifying VPN rules to limit access to specific, trusted IP addresses is also recommended. Additionally, users of Check Point Live Patch (CPLP) should check if they have received all available protections for the two flaws since September 9.
In a worst-case scenario, exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to sensitive data or disrupt critical business operations. As such, it is essential that system administrators prioritize applying security updates as soon as possible and take proactive measures to limit potential damage.
To safeguard against this threat, we recommend the following:
* Immediately install security updates addressing CVE-2026-85102 and CVE-2026-85103.
* Modify VPN rules to limit access to specific, trusted IP addresses for those using the ‘Site-to-Site VPN’ component.
* Verify that Check Point Live Patch (CPLP) users have received all available protections since September 9.
By taking these precautions, organizations can significantly reduce their risk of falling victim to a successful attack and ensure the continued security and integrity of their systems.
Source: Bleeping Computer — 2026-09-12