Critical Check Point VPN Flaws (CVE‑2026‑85102 & CVE‑2026‑85103) Enable Remote Code Execution – Exploitation Imminent
What It Is – The Dutch Nationaal Cyber Security Centrum (NCSC) has flagged two critical vulnerabilities in Check Point’s VPN gateway: an improper certificate validation (CVE‑2026‑85102) and a heap overflow in the ASN.1 decoder (CVE‑2026‑85103). Both allow a remote attacker to execute arbitrary code on Security Gateways and Management Servers.
Exploitability – No public proof‑of‑concept has been released, but the NCSC rates the likelihood of exploitation as high and expects active attempts soon. The CVSS scores published by Check Point are 9.8 (critical) for each flaw.
Affected Products – Check Point VPN releases R81.20, R82, R82.10, R81.10.x, R82.00.x and end‑of‑support versions R80‑R81.10 are vulnerable. The flaws are patched in LivePatch Take 24 for the supported releases and in later hot‑fix accumulators.
Why It Matters for Trust & Control Assurance
- Patch Management Discipline – Demonstrating that critical patches are applied within vendor‑defined timelines satisfies a core control objective (maintain up‑to‑date security patches) that maps to dozens of frameworks (e.g., NIST CSF PR.IP‑12, ISO 27001 A.12.6).
- Evidence of Due Diligence – Continuous monitoring of patch status and retaining immutable proof of remediation provides audit‑ready evidence for regulators and enterprise buyers.
- Defensible Incident‑Response Posture – Knowing the exact version and patch level of each VPN gateway reduces the attack surface and limits the scope of any potential breach, supporting a credible incident‑response plan.
Recommended Actions
- Verify the current version of every Check Point VPN gateway against the vendor’s patch matrix.
- Deploy the LivePatch Take 24 updates (or the appropriate hot‑fix accumulator) immediately; for LivePatch users confirm automatic mitigation is active.
- For Site‑to‑Site VPN configurations, restrict rule sets to trusted IP ranges while patches are applied.
- Record patch‑deployment timestamps in a centralized control‑evidence repository to satisfy audit requirements.
Source: BleepingComputer – Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent