UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

Check Point VPN Flaw 2026: Patch Now, NCSC Warns

London · Servnet News Desk · IT infrastructure analysis4 min read
Share

The Dutch national cyber agency has told organisations running Check Point VPN to expect exploitation of two critical flaws within days. In our assessment, organisations that haven't yet applied the 9 September fixes should treat this as a same-week patching priority rather than routine maintenance.

Check Point VPN flaw disclosure-to-exploitation window…
W0W1W2W3W4Fixes released (LivePatch…1wNCSC imminent-exploitatio…1wEditorial projection…2wTotal: 4 weeks end-to-end
View the data behind this chart
Check Point VPN flaw disclosure-to-exploitation window…
PhaseStarts (week)Duration (weeks)
Fixes released (LivePatch…01
NCSC imminent-exploitation…11
Editorial projection…22

Two critical bugs, one unauthenticated route to full compromise

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning that exploitation of CVE-2026-85102 and CVE-2026-85103 in Check Point VPN is imminent; the NCSC says no public proof-of-concept exploit has been reported. CVE-2026-85102 stems from improper validation of certificate data during VPN negotiation, letting a remote attacker execute arbitrary code on a Security Gateway. CVE-2026-85103 is a heap-based buffer overflow in the VPN certificate ASN.1 decoder, which can enable remote code execution on both Security Gateways and Security Management Servers. Both carry a CVSS score of 9.8, as reported by The Hacker News.

The flaws are described as enabling unauthenticated remote code execution, which is exactly why the NCSC has flagged the likelihood and impact of attacks as high. The agency says successful exploitation could hand an attacker full control of a system, access to confidential data, and the ability to disrupt operations.

Why the warning window matters more than the absence of a public exploit

Check Point disclosed both issues itself on 9 September 2026, alongside advisories sk1000117 and sk1000118, and said it had no indication of active exploitation at the time. That's the calm before the storm pattern the NCSC is now reacting to: a vendor-led disclosure with fixes already available typically triggers a race between defenders patching and attackers reverse-engineering the fix to build a working exploit. The NCSC's assessment that exploitation attempts will occur soon reflects that race, not evidence of attacks already under way.

For UK infrastructure teams, that timing gap is the entire opportunity. Every day between disclosure and a patched estate is a day of exposure on an internet-facing VPN gateway, which is precisely the kind of asset that sits at the top of any sound vulnerability management priority list.

Which versions are exposed and what actually fixes them

The affected branches are R81.20, R82 and R82.10, at or below the vulnerable Jumbo Hotfix Accumulator take levels set out in Check Point's advisories sk1000117 and sk1000118. Check Point also lists R80 through R80.40, R81 and R81.10 as end-of-support releases that sit outside the scope of the published fixes, per BleepingComputer's reporting. A Canadian Centre for Cyber Security advisory cited by The Hacker News broadens the picture further, listing Security Gateway, Security Management Server and Spark Firewall as affected product families — so this isn't confined to perimeter VPN boxes alone.

Check Point's fix is delivered through LivePatch Take 24 for R81.20, R82 and R82.10. Alternatively, it is delivered through Jumbo Hotfix Accumulator Take 44 or later (R82.10), Take 126 or later (R82), and Take 166 or later (R81.20). Spark customers need Spark R82.00.10 Build 2325 or later, or Spark R81.10.17 Build 4968 or later. R82.20 is not affected by either flaw.

  • LivePatch Take 24 (R81.20, R82, R82.10) — no reboot required for supported CPLP configurations; check whether your configuration is actually covered
  • Jumbo Hotfix Accumulator Take 44+/126+/166+ for R82.10/R82/R81.20 respectively
  • Spark R82.00.10 Build 2325+ or Spark R81.10.17 Build 4968+
  • End-of-support branches (R80–R80.40, R81, R81.10) are not covered by the published fixes — migration or replacement is required
Illustration: Check Point VPN Flaw 2026: Patch Now, NCSC Warns

The catch with automatic mitigation

Check Point says CPLP users should have received protections automatically for supported configurations since 9 September, without a server reboot, according to its community forum posts. Coverage applies to R82.10, R82 and R81.20 only, and not every configuration is supported — so teams need to actively confirm protection status rather than assume it. For organisations still running Site-to-Site VPN components, the NCSC's interim advice is to tighten VPN rules to permit only specific, trusted IP addresses while patching is completed.

What this means for UK buyers beyond this week's patch cycle

A 9.8-rated, unauthenticated remote code execution pair on a widely deployed enterprise VPN platform is the kind of event that should prompt a wider conversation, not just a patch ticket. Teams relying on network security solutions built around perimeter VPN concentrators are carrying concentration risk: one appliance family, one certificate-handling bug, and a large slice of remote access goes dark or gets compromised at once.

That's the argument increasingly being made for a phased VPN to ZTNA migration, where remote access is brokered per-application rather than through a single always-on gateway that becomes a high-value target the moment a flaw like this surfaces. Pairing that shift with a zero trust access model reduces the blast radius of the next VPN-grade CVE, whenever it lands. In the meantime, organisations that can't patch immediately should lean on managed detection & response to watch for anomalous authentication and gateway process behaviour, and treat this as a live input into ransomware protection planning, given how frequently VPN footholds precede extortion incidents.

Patch thresholds by affected Check Point branch (per Check…
R81.20R82R82.10Vulnerable JHF levelTake ≤165Take ≤125Take ≤43Fixed JHF levelTake 166+Take 126+Take 44+LivePatch fixTake 24Take 24Take 24CVSS score of flaws9.89.89.8
View the data behind this chart
Patch thresholds by affected Check Point branch (per Check…
R81.20R82R82.10
Vulnerable JHF levelTake ≤165Take ≤125Take ≤43
Fixed JHF levelTake 166+Take 126+Take 44+
LivePatch fixTake 24Take 24Take 24
CVSS score of flaws9.89.89.8

Action checklist for this week

Confirm your Check Point branch and current hotfix take level against the vulnerable thresholds before assuming you're covered. Apply LivePatch Take 24 or the relevant Jumbo Hotfix Accumulator immediately, verify CPLP auto-mitigation actually applied to your configuration, restrict Site-to-Site VPN access to trusted IPs as an interim control, and flag any end-of-support branch (R80.x, R81, R81.10) for urgent migration since these releases are not covered by the published fixes. Anyone managing a broader estate should fold this into ongoing cyber security services review cycles rather than treating it as a one-off fire drill.

Share
Key takeaways
  • Dutch NCSC rates exploitation likelihood and impact as high for CVE-2026-85102 and CVE-2026-85103, both CVSS 9.8, with attempts expected imminently
  • Fixes landed 9 September 2026 via LivePatch Take 24 or specific Jumbo Hotfix Accumulator builds — R82.20 is unaffected
  • End-of-support branches R80–R80.40, R81 and R81.10 are not covered by the published fixes and need migration or replacement, not just a hotfix
  • Concentrated VPN exposure is a recurring risk pattern — ZTNA and zero trust reduce reliance on a single gateway class
Frequently asked

FAQs — Check Point VPN Flaw 2026

What are CVE-2026-85102 and CVE-2026-85103?

CVE-2026-85102 is improper certificate validation during VPN negotiation that allows remote code execution on a Security Gateway; CVE-2026-85103 is a heap-based buffer overflow in the VPN certificate ASN.1 decoder allowing remote code execution on Security Gateways and Security Management Servers. Both are rated CVSS 9.8.

Has a working exploit been published?

No. As of the Dutch NCSC's warning, no public proof-of-concept exploit had been reported, but the agency still assesses exploitation as imminent given the severity and the time since disclosure.

Which Check Point versions need patching?

R81.20, R82 and R82.10 are affected at or below the vulnerable Jumbo Hotfix Accumulator take levels. R80 through R80.40, R81 and R81.10 are listed as end-of-support releases not covered by the published fixes. R82.20 is not affected by either flaw.

How do I patch without waiting for a full maintenance window?

Check Point Live Patch (CPLP) delivers Take 24 without a reboot for supported R81.20, R82 and R82.10 configurations, though it doesn't cover every configuration — verify protection status directly rather than assuming coverage, and consider tightening network security solutions rules in the interim.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111