Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tech
Critical Check Point VPN flaws exploitation is imminent
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
Although no public proof-of-concept (PoC) exploit has been reported, the agency is urging organizations to install the security updates addressing the two issues as soon as possible.
“The NCSC assesses the likelihood of exploitation and the potential impact as high and expects exploitation attempts to occur soon,” the NCSC warns.
Check Point VPN is an enterprise solution that allows remote employees to securely connect to their company’s internal network via encrypted connections.
On September 9, Check Point issued fixes for the flaws along with separate security advisories describing them: sk1000117 and sk1000118.
CVE-2026-85102 is an improper validation of certificate data during VPN negotiation that a remote attacker could exploit to execute arbitrary code on a Security Gateway.
CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder that could allow remote code execution on Security Gateways and Security Management Servers.
Affected releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, along with the end-of-support (EoS) versions R80 through R80.40, R81, and R81.10.
Both flaws are fixed by Check Point LivePatch Take 24 for R81.20, R82, and R82.10, while fixes are also included in the following versions:
- R82.10 Jumbo Hotfix Accumulator Take 44 or later
- R82 Jumbo Hotfix Accumulator Take 126 or later
- R81.20 Jumbo Hotfix Accumulator Take 166 or later
- Spark R82.00.10 Build 2325 or later
- Spark R81.10.17 Build 4968 or later
Check Point VPN version R82.20 is not affected by either flaw.
NCSC warned that exploitation of the flaws could allow an attacker to take full control of a system, view or modify confidential data, and disrupt operations.
The organization urges system administrators to apply the security updates as soon as possible. At the same time, for those using the ‘Site-to-Site VPN’ component, the advice is to modify VPN rules to limit access to specific, trusted IP addresses.
According to a post in Check Point’s community forums, users of Check Point Live Patch (CPLP) should have received all available protections for the two flaws since September 9, and those fixes should apply even without a server reboot.
CPLP users should check if they are protected by this automatic mitigation, as it is not available for versions other than R82.10, R82, and R81.20 and doesn’t support all configurations.
You must be logged in to post a comment Login