Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
AdvisoryCheck Point VPNSecurity GatewayOur summary
The Dutch NCSC has issued an urgent alert regarding the likely immediate exploitation of two critical vulnerabilities in Check Point VPN, specifically CVE-2026-85102 and CVE-2026-85103. These flaws permit remote attackers to gain control of Security Gateway and Security Management Server components by exploiting improper certificate validation and a heap overflow in the ASN.1 decoder. Although no public exploit code is currently available, the agency recommends applying security updates immediately to mitigate the risk of data theft and operational disruption.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.