The Netherlands’ national cybersecurity agency has issued an urgent warning over two critical vulnerabilities in Check Point VPN products that could allow attackers to take control of internet-facing security systems without first logging in.
The flaws, tracked as CVE-2026-85102 and CVE-2026-85103, both carry a severity score of 9.8 out of 10.
The Dutch National Cyber Security Centre, or NCSC, says exploitation attempts are expected soon and has urged organisations to install available security updates immediately.
Check Point says it has not found evidence that either vulnerability is currently being exploited in real-world attacks.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Attackers would not need a username or password
The most concerning part of both vulnerabilities is that an attacker does not need an existing account.
CVE-2026-85102 affects how Check Point Security Gateway validates certificate information while establishing a VPN connection.
Improper certificate validation could allow a remote attacker to bypass expected security checks and execute malicious code on the gateway.
CVE-2026-85103 involves a memory-management flaw known as a heap overflow in the way VPN certificate data is decoded.
That flaw can also result in remote code execution.
In simple terms, a specially crafted VPN connection could potentially cause the security appliance itself to execute instructions supplied by the attacker.
CERT-EU says both vulnerabilities can be exploited remotely and without authentication under affected VPN configurations.
That matters because a VPN gateway normally sits at the edge of an organisation’s network.
It is supposed to protect internal systems from the public internet.
A vulnerability in the gateway can therefore turn the defensive perimeter itself into an entry point.
What are VPN gateways and remote code execution?
A VPN, or virtual private network, creates an encrypted connection between a user or another network and an organisation’s systems.
Companies use VPNs to allow employees to work remotely or to securely connect offices in different locations.
A security gateway is the device controlling that connection.
Remote code execution, commonly called RCE, is one of the most serious classes of software vulnerability. It means an attacker may be able to make a vulnerable machine run commands or programs of the attacker’s choosing.
If the affected machine is a network-security appliance, successful exploitation can be particularly serious because that device may have trusted access to other systems.
Security Gateway, management servers and Spark products affected
CERT-EU says the vulnerabilities affect several generations of Check Point products.
Affected Security Gateway releases include versions across R80, R81 and R82 families. Certain Spark Firewall products are also vulnerable.
CVE-2026-85103 additionally affects Security Management Server deployments.
The flaws become relevant where affected systems are configured for either Remote Access VPN or Site-to-Site VPN.
Remote Access VPN is commonly used by employees connecting from outside the office.
Site-to-Site VPN connects entire corporate networks — for example, linking a Mumbai office with a Bengaluru data centre through an encrypted tunnel.
CERT-EU has told organisations to prioritise internet-facing and perimeter systems when applying fixes.
Why Dutch authorities expect attackers to move quickly
Public disclosure changes the threat environment.
Once a critical vulnerability receives a CVE number and enough technical information becomes available, security researchers begin analysing it.
Attackers do the same.
They can compare vulnerable and patched versions of software to identify what changed and potentially reconstruct how the flaw works.
This is why the period immediately after publication of a critical vulnerability can become dangerous.
The Dutch NCSC rates both the probability of exploitation and the potential damage as high.
Check Point itself has urged customers to install the latest Jumbo Hotfix and says users with Live Patch enabled are receiving protection automatically.
For organisations that cannot immediately patch every system, Check Point has also provided mitigations involving tighter VPN rules.
SecurityWeek reported that Site-to-Site VPN users can restrict UDP ports 500 and 4500 to known peer IP addresses, although that mitigation does not apply to every Spark configuration.
VPN appliances have become prime targets for attackers
The urgency reflects a broader cybersecurity pattern.
Attackers increasingly target firewalls, VPN gateways and remote-access appliances because compromising one perimeter device can provide a direct path into an organisation.
These systems are also frequently reachable from the public internet by design.
Once inside, attackers may attempt to steal credentials, move laterally across the network, deploy ransomware or maintain long-term access.
That makes patch speed unusually important.
A vulnerable application buried on an employee laptop may require several additional steps before an attacker reaches critical infrastructure.
A vulnerable security gateway can already be standing at the front door.
For Check Point customers, the question is therefore not simply whether attacks have been observed yet.
The safer assumption is that once technical details become widely understood, scanning for vulnerable systems will follow.
What this means for you: This warning mainly affects organisations running Check Point VPN and security infrastructure, not ordinary VPN app users. IT teams should identify affected gateways immediately, apply the latest hotfixes and restrict exposed VPN services wherever possible.
The420 Insight: The irony of perimeter-security flaws is that the product meant to keep attackers out can become their shortest route inside. With two 9.8-rated vulnerabilities now public, the window between disclosure and mass scanning could be more important than whether exploitation has been observed today.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics