Quick nutshell
The Dutch Nationaal Cyber Security Centrum (NCSC) just raised the alarm about two nasty Check Point VPN bugs (CVE-2026-85102 and CVE-2026-85103) and says exploitation is likely very soon — imminent exploitation, in plain speak. No public proof-of-concept has surfaced yet, but that hasn’t stopped the panic button from being gently, but firmly, pressed.
These issues can let a remote attacker run code on affected machines during VPN negotiation or by abusing the VPN certificate parser — in other words, this is the kind of bug that can give an attacker full control of a gateway or management server, see or change confidential data, and generally make a mess.
Details and what to do (fast)
Here’s the practical stuff you need right now — who’s affected, what’s fixed, and quick mitigation tips you can use before you’ve had your morning coffee.
- Affected releases: R81.20, R82, R82.10, R81.10.x, R82.00.x and older end-of-support lines including R80 → R80.40, R81, and R81.10.
- Not affected: Check Point VPN R82.20 is reported as not vulnerable to these two issues.
- Nature of the flaws: CVE-2026-85102 is improper validation of certificate data during VPN negotiation; CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder. Both can lead to remote code execution.
Fix availability:
- LivePatch Take 24 covers R81.20, R82, and R82.10 (check your LivePatch status).
- Other fixed builds include:
- R82.10 Jumbo Hotfix Accumulator Take 44 or later
- R82 Jumbo Hotfix Accumulator Take 126 or later
- R81.20 Jumbo Hotfix Accumulator Take 166 or later
- Spark R82.00.10 Build 2325 or later
- Spark R81.10.17 Build 4968 or later
If you use Check Point Live Patch (CPLP), those using R82.10, R82, or R81.20 should have received automatic protections since the fixes were released. That said, CPLP doesn’t cover every configuration or every version, so don’t assume you’re safe — double-check.
Immediate mitigation steps (if you can’t patch right this instant):
- Apply the vendor fixes as a top priority — if the update window is open, close it.
- For Site-to-Site VPN users: restrict VPN rules to only trusted IP addresses — less exposure, fewer headaches.
- Verify LivePatch/CPLP status and confirm whether your specific configuration is covered.
- Monitor logs and alerts for unusual VPN negotiation activity and be ready to isolate affected systems.
Bottom line: treat this as high priority. The Dutch NCSC believes the chance of abuse and the fallout are both high. Patch, restrict, and double-check — then have a celebratory (but cautious) coffee.