Critical

Check Point, VPN, CVE-2026-85102, CVE-2026-85103, Remote Code Execution, NCSC, Edge Security

Check Point VPN CVE-2026-85102: RCE, Exploit Imminent

Check Point VPN CVE-2026-85102 and CVE-2026-85103 are two CVSS 9.8 remote code execution flaws in Security Gateways. The Dutch NCSC warns exploitation is imminent. Patch now.

Check Point VPN CVE-2026-85102 and CVE-2026-85103 are two critical, CVSS 9.8 remote code execution flaws in Check Point Security Gateways, and the Dutch National Cyber Security Centre (NCSC) is warning that exploitation is imminent even though no public proof-of-concept has appeared yet. The NCSC assesses both the likelihood of exploitation and the potential impact as high and urges organizations to install the fixes as soon as possible. Check Point issued patches on September 9, 2026 in advisories sk1000117 and sk1000118.

CVE-2026-85102 is an improper validation of certificate data during VPN negotiation (CWE-295) that a remote attacker can use to execute code on a Security Gateway. CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder (CWE-122) that allows remote code execution on both Security Gateways and Security Management Servers. Because these are network-reachable, unauthenticated flaws on the exact device that terminates remote access, a successful attack can hand an attacker full control of the perimeter.

Affected releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, plus the end-of-support versions R80 through R80.40, R81, and R81.10. Both are fixed by Check Point LivePatch Take 24 for R81.20, R82, and R82.10, and in the corresponding maintenance versions. Check Point VPN R82.20 is not affected by either flaw.

How do you mitigate CVE-2026-85102 if you cannot patch immediately?

For deployments using the Site-to-Site VPN component, Check Point advises modifying VPN rules to restrict access to specific, trusted IP addresses, which shrinks the pool of hosts that can reach the vulnerable negotiation path. Customers on Check Point Live Patch (CPLP) should have received protections automatically since September 9 without a server reboot, but only on R82.10, R82, and R81.20, and not for all configurations, so administrators must confirm the automatic mitigation actually applied rather than assume it did.

Why act before a public exploit exists?

Because the gap between a national CERT saying exploitation is imminent and a working exploit circulating is short, and it is exactly the window defenders should use. EPSS still sits in the low percentiles and neither CVE is in CISA KEV yet, but those signals lag reality for a freshly patched, unauthenticated 9.8 on an internet-facing VPN. Edge appliances are among the most-targeted assets precisely because one flaw yields network entry, so a 9.8 here deserves emergency handling regardless of the current EPSS number.

Detail

Value

CVEs

CVE-2026-85102 (CWE-295), CVE-2026-85103 (CWE-122)

CVSS

9.8 Critical each

Impact

Unauthenticated RCE on Gateways and Management Servers

Affected

R81.20, R82, R82.10, R81.10.x, R82.00.x, plus EoS R80-R81.10

Fix

LivePatch Take 24; R82.20 not affected

Status

No public PoC; NCSC warns exploitation imminent

Our read

An unauthenticated 9.8 on a VPN gateway is the definition of a perimeter choke point, and a national CERT flagging imminent exploitation is the clearest possible signal to move now, not after a PoC lands. The recurring lesson with edge devices is that they must be patched on emergency timelines and their management surfaces kept off the open internet, because attackers reliably weaponize these bugs within days of disclosure. The defensible posture is to patch to LivePatch Take 24 immediately, verify the automatic mitigation actually applied, restrict VPN rules to trusted IPs where possible, and confirm from the outside that the gateway is no longer exposed.

Reporting by BleepingComputer; severity and mitigation detail per the Dutch NCSC and Check Point advisories sk1000117 and sk1000118. Sources linked above.

Related: What is a zero-day? and How to prioritize vulnerabilities.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.