Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected Imminently
Dutch NCSC Warns of Critical Check Point VPN Flaws (TL-2026-2463) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-12. It has no confirmed attribution, affects Check Point Software Technologies Quantum Security Gateway, references 2 CVEs (CVE-2026-85102, CVE-2026-85103), maps to 8 MITRE ATT&CK techniques (T1005, T1190, T1499.004), and is covered by 9 detection rules and 14 indicators of compromise.
Key facts for TL-2026-2463
- Threat ID
- TL-2026-2463
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-12
- Last reviewed
- 2026-09-12
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target regions
- netherlands, Global
- Detection rules
- 9
- Indicators of compromise
- 14
Malware and tooling in Dutch NCSC Warns of Critical Check Point VPN Flaws
Malware and tooling: AgendaCrypt
Check Point disclosed two unauthenticated remote-code-execution flaws in its VPN certificate-handling path — CVE-2026-85102 (improper certificate validation during VPN negotiation) and CVE-2026-85103 (heap overflow in the VPN certificate ASN.1 decoder) — both CVSS 9.8, affecting Security Gateway, Security Management Server, and Spark Firewall. Dutch NCSC issued a public alert on 2026-09-12 assessing exploitation likelihood and impact as high and expecting large-scale exploitation attempts soon; Check Point found the bugs internally and reports no public PoC or confirmed in-the-wild exploitation as of publication.
How Dutch NCSC Warns of Critical Check Point VPN Flaws works
CVE-2026-85102 and CVE-2026-85103 both target the same pre-authentication attack surface: certificate handling in Check Point's VPN negotiation logic, before a peer is authenticated. CVE-2026-85102 (CWE-295, Improper Certificate Validation) is a flaw in how the VPN connection-setup process validates certificate data presented during negotiation, allowing an unauthenticated remote attacker to push the negotiation far enough to execute arbitrary code on the Security Gateway. CVE-2026-85103 (CWE-122, Heap-based Buffer Overflow) is a memory-corruption bug in the ASN.1 decoder used to parse VPN certificates; an attacker can trigger the overflow simply by sending a malicious certificate, and because the same decoder runs on Security Management Server as well as Security Gateway, this flaw has the broader blast radius — compromising the management plane could bypass downstream security controls across an entire managed fleet. Both CVEs carry CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and require no credentials and no user interaction.
Affected products are Check Point Quantum Security Gateway, Quantum Security Management Server, and Spark Firewall (centrally and locally managed) on R81.20, R82, and R82.10 below their respective patched Jumbo Hotfix Accumulator thresholds, plus all end-of-support branches (R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10), which receive no further fixes. R82.20 is confirmed unaffected. Check Point published advisories sk1000117 and sk1000118 on 2026-09-07 with LivePatch Take 24 bundles that began automatic deployment on 2026-09-09, alongside manual Jumbo Hotfix Accumulator and Spark Firewall build updates. The only interim workaround — disabling implied VPN rules and restricting UDP/500 and UDP/4500 to known peer IP addresses — applies solely to Site-to-Site VPN; there is no mitigation for Remote Access VPN or locally managed Spark Firewalls short of patching.
Dutch NCSC's 2026-09-12 alert assessed both exploitation likelihood and potential impact as high, warning that active, large-scale misuse attempts are expected soon and could lead to system takeover, data theft or modification, and service disruption. As of the CISA KEV catalog snapshot dated 2026-09-11 (1,709 entries), neither CVE appears in KEV, and no public proof-of-concept exploit has surfaced. Industry analysis frames these disclosures as part of a broader 2026 pattern of pre-authentication 'auth gap' vulnerabilities in edge/perimeter software (also seen in PaperCut, N-able, Microsoft, SAP, and Ivanti products), where systems process untrusted data before confirming requestor legitimacy. Exposure scanning cited in that analysis found roughly 13,754 internet-facing Check Point VPN devices, including about 1,021 identified specifically as Quantum Security Gateways — a substantial pool of targets if mass exploitation begins.
A Check Point staff member clarified a scope detail not captured in the formal advisories: CVE-2026-85103's certificate-processing flaw runs through CPCA (Check Point Certificate Authority), which every Security Management Server operates independent of whether VPN is actively configured or in use, meaning management servers must be patched even in deployments where VPN itself is disabled or unused.
These two CVEs are explicitly distinct from Check Point's other 2026 VPN security incidents: CVE-2026-50751 (CVSS 9.3), an IKEv1 Remote Access/Mobile Access certificate-validation logic flaw enabling authentication bypass, actively exploited since 2026-05-07 against a few dozen targeted organizations and linked by Check Point to a Qilin ransomware affiliate before CISA added it to KEV on 2026-06-09; its sibling CVE-2026-50752 (CVSS 7.4), a related IKEv1 certificate-validation weakness enabling man-in-the-middle attacks on Site-to-Site VPN connections under specific conditions, with no observed in-the-wild exploitation; and CVE-2026-16232, another zero-day Check Point warned customers about earlier in the year. CVE-2026-85102/85103 stem from certificate validation and ASN.1 decoding defects in current VPN negotiation and CPCA processing, not the deprecated IKEv1 key-exchange logic exploited in CVE-2026-50751/50752, and no source ties Qilin or any other named actor to CVE-2026-85102/85103 specifically.
MITRE ATT&CK techniques used in TL-2026-2463
Collection
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1499.004 Application or System Exploitation
Resource Development
T1587.004 Exploits; T1588.005 Exploits
Reconnaissance
T1592.002 Software; T1595.001 Scanning IP Blocks; T1595.002 Vulnerability Scanning
Affected products and versions in Dutch NCSC Warns of Critical Check Point VPN Flaws
- Check Point Software Technologies — Quantum Security Gateway
Vulnerable versions: R81.20 (Jumbo HFA Take 165 or below); R82 (Jumbo HFA Take 125 or below); R82.10 (Jumbo HFA Take 43 or below); R80; R80.10; R80.20; R80.30; R80.40; R81; R81.10 (all end-of-support)
Fixed in: R81.20 with LivePatch Take 24 or Jumbo HFA Take 166+; R82 with LivePatch Take 24 or Jumbo HFA Take 126+; R82.10 with LivePatch Take 24 or Jumbo HFA Take 44+; R82.20 (confirmed not affected) - Check Point Software Technologies — Quantum Security Management Server
Vulnerable versions: R81.20 (Jumbo HFA Take 165 or below); R82 (Jumbo HFA Take 125 or below); R82.10 (Jumbo HFA Take 43 or below)
Fixed in: R81.20/R82/R82.10 with LivePatch Take 24 or the corresponding Jumbo HFA thresholds above - Check Point Software Technologies — Spark Firewall (centrally and locally managed)
Vulnerable versions: R82.00.x below Build 2325; R81.10.x below Build 4968
Fixed in: R82.00.10 Build 2325+; R81.10.17 Build 4968+
Remediation for Dutch NCSC Warns of Critical Check Point VPN Flaws
Patches
- LivePatch Take 24 (BUNDLE_URGENT_SECURITY_UPDATE_R81_20_AUTOUPDATE / R82_AUTOUPDATE / R82_10_AUTOUPDATE)
- Jumbo Hotfix Accumulator R82.10 Take 44 or above
- Jumbo Hotfix Accumulator R82 Take 126 or above
- Jumbo Hotfix Accumulator R81.20 Take 166 or above
- Spark Firewall R82.00.10 Build 2325 or above
- Spark Firewall R81.10.17 Build 4968 or above
Immediate actions
- Apply Check Point LivePatch Take 24 on R81.20, R82, and R82.10 Security Gateways and Security Management Servers, or install the equivalent Jumbo Hotfix Accumulator (R82.10 Take 44+, R82 Take 126+, R81.20 Take 166+)
- Update Spark Firewall (centrally and locally managed) to R82.00.10 Build 2325+ or R81.10.17 Build 4968+
- For Site-to-Site VPN deployments only, disable implied VPN rules and manually restrict VPN access for UDP/500 and UDP/4500 to specific known peer IP addresses as an interim measure
Workarounds
- Site-to-Site VPN only: disable implied VPN rules and manually define VPN access for UDP/500 and UDP/4500 restricted to specific peer IP addresses; this does not apply to Remote Access VPN or locally managed Spark Firewalls, which have no available workaround
Longer-term hardening
- Migrate end-of-support branches (R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10) to a currently supported, patched release, since no fix is planned for end-of-support versions
- Plan upgrade paths to R82.20, which Check Point confirms is unaffected by either CVE
- Enable Check Point LivePatch for automatic deployment of future urgent security bundles
CVEs associated with Dutch NCSC Warns of Critical Check Point VPN Flaws
CVE-2026-85102, CVE-2026-85103
Weaknesses (CWE) in Dutch NCSC Warns of Critical Check Point VPN Flaws
CWE-295, CWE-122
Timeline of Dutch NCSC Warns of Critical Check Point VPN Flaws
- Check Point publishes sk1000118, disclosing CVE-2026-85103 (heap overflow in the VPN certificate ASN.1 decoder) affecting Security Gateway, Security Management Server, and Spark Firewall.
- Check Point publishes sk1000117, disclosing CVE-2026-85102 (improper certificate validation during VPN negotiation) affecting Security Gateway and Spark Firewall.
- Check Point begins automatic LivePatch Take 24 deployment for R81.20, R82, and R82.10 customers with LivePatch enabled.
- A Check Point staff member clarifies that CVE-2026-85103's certificate-processing flaw runs through CPCA, which every Security Management Server operates independent of active VPN usage, so management servers must be patched even where VPN is disabled.
- CISA's Known Exploited Vulnerabilities catalog snapshot (1,709 entries) is published without CVE-2026-85102 or CVE-2026-85103 listed, indicating no confirmed active exploitation as of this date.
- BleepingComputer, SecurityWeek, Cybersecurity News, Security Online, forkast.news, sqmagazine, and hendryadrian.com publish coverage and technical analysis of the NCSC alert and the two CVEs.
- NCSC and Check Point jointly recommend immediate patching, and for Site-to-Site VPN deployments, disabling implied VPN rules and restricting UDP/500 and UDP/4500 to known peer IP addresses.
- Dutch NCSC (NCSC-NL) issues a public alert assessing exploitation likelihood and impact as high and warning that large-scale exploitation attempts are expected soon.
Sources cited for Dutch NCSC Warns of Critical Check Point VPN Flaws
- Dutch NCSC Alert: Kritieke kwetsbaarheden in Check Point VPN-producten met actief misbruik verwacht
- Check Point sk1000117 — CVE-2026-85102
- Check Point sk1000118 — CVE-2026-85103
- Dutch NCSC critical Check Point VPN flaws, exploitation is imminent
- NVD — CVE-2026-85102
- NVD — CVE-2026-85103
- CISA Known Exploited Vulnerabilities Catalog (1,709 entries; CVE-2026-85102/85103 not listed)
- Check Point Patches Critical VPN Vulnerabilities
- Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks
- Check Point Quantum VPN Drops Two CVSS 9.8 CVEs in the Same Certificate Path — VPN Infrastructure Joins the Auth Gap
- CVE-2026-85102 & 85103: Check Point VPN Flaws 9.8 CVSS RCE
- Check Point VPN Flaws CVE-2026-85102 and 85103 Rated 9.8
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
- Patch Critical Check Point VPN Vulnerability (CVE-2026-50751 / CVE-2026-50752)
- Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751)
More in vulnerability
- VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read (CVE-2026-73324)
- GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706, CVSS 10.0)
- CVE-2026-0310: PAN-OS XML Processing Out-of-Bounds Write Enables Unauthenticated Root RCE
- Endor Labs Discloses 14 Critical/High Vulnerabilities Across Seven AI Orchestration Platforms (NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, Apache Airflow)
- CVE-2025-25249: Fortinet Heap-Based Buffer Overflow Exploited to Deploy PivotC2 RAT on FortiGate Devices
Detection coverage for TL-2026-2463
As of 2026-09-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2463 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.