Critical Remote‑Code‑Execution Flaws (CVE‑2026‑85102, CVE‑2026‑85103) in Check Point VPN Products Prompt Immediate Patch
What Happened – The Dutch National Cyber Security Centre (NCSC) disclosed two critical Check Point VPN vulnerabilities (CVE‑2026‑85102 and CVE‑2026‑85103) each scoring 9.8 CVSS. Both enable unauthenticated remote‑code execution on Security Gateways and Management Servers. Check Point released hot‑fixes on 9 Sept 2026, but the NCSC warns exploitation is likely imminent.
Why It Matters for Trust & Control Assurance
- Unpatched VPN gateways break the “secure remote access” control objective, leaving a beachhead for attackers and eroding the evidential trail needed for audit readiness.
- Continuous control‑assurance programs must capture patch‑management evidence and verify that network‑perimeter rules (e.g., IP‑allow lists) are enforced in real time.
Who Is Affected – Enterprises that rely on Check Point site‑to‑site or remote‑access VPNs across technology, finance, healthcare, and other sectors.
Recommended Actions
- Deploy the Check Point hot‑fixes (or LivePatch where supported) for all affected versions immediately.
- Harden VPN policies: disable implied rules, restrict access to known, trusted IP ranges, and enforce least‑privilege connectivity.
- Integrate patch‑status and VPN‑rule compliance into your continuous monitoring platform to generate defensible audit evidence.
Technical Notes
- CVE‑2026‑85102: Flaw in VPN negotiation bypasses authentication checks, leading to code execution.
- CVE‑2026‑85103: Heap overflow in the certificate ASN.1 decoder also results in remote code execution.
- Both are exploitable over the network without credentials; no public PoC yet, but high likelihood of active exploitation.
Source: SecurityAffairs article