Select a theme from the list.
Insights

From our experts

Latest
Phishing Study Finds Click Rates Are Hiding the Metrics That Actually MatterClaude Distillation Campaigns Turn AI Access Into an Industrial Data-Theft MarketCheck Point VPN Flaws Put Enterprise Gateways on an Urgent Patch ClockMicrosoft Maps the Hidden Attack Paths Connecting Serverless Apps to Cloud ControlBrevo Breach Turns Trusted Trezor Emails Into Wallet-Stealing PhishingCisco Firewall Manager Flaws Become Launchpads for Espionage and Qilin RansomwareGitLab File-Read Flaw Attracts Attackers Within a Day of DisclosureSogou Input Tool Turned a Trusted Windows Feature Into a Backdoor LauncherStolen Police Credentials Open Florida Driver Database to IntrudersGigabud Hides Banking Fraud Inside Android Work ProfilesSurfshark Test Server Breach Exposes the Security Gap Between Development and ProductionAI-Polished CEO Fraud Targets Finance Teams With Million-Email BlitzPhishing Study Finds Click Rates Are Hiding the Metrics That Actually MatterClaude Distillation Campaigns Turn AI Access Into an Industrial Data-Theft MarketCheck Point VPN Flaws Put Enterprise Gateways on an Urgent Patch ClockMicrosoft Maps the Hidden Attack Paths Connecting Serverless Apps to Cloud ControlBrevo Breach Turns Trusted Trezor Emails Into Wallet-Stealing PhishingCisco Firewall Manager Flaws Become Launchpads for Espionage and Qilin RansomwareGitLab File-Read Flaw Attracts Attackers Within a Day of DisclosureSogou Input Tool Turned a Trusted Windows Feature Into a Backdoor LauncherStolen Police Credentials Open Florida Driver Database to IntrudersGigabud Hides Banking Fraud Inside Android Work ProfilesSurfshark Test Server Breach Exposes the Security Gap Between Development and ProductionAI-Polished CEO Fraud Targets Finance Teams With Million-Email Blitz
Security Insight

Check Point VPN Flaws Put Enterprise Gateways on an Urgent Patch Clock

Check Point VPN Flaws Put Enterprise Gateways on an Urgent Patch Clock
Photo by Tima Miroshnichenko on Pexels

The Dutch National Cyber Security Centre has warned that exploitation of two critical Check Point VPN vulnerabilities is likely to occur soon. Both weaknesses can enable remote code execution in affected security gateways, making rapid patching and exposure reduction essential.

News Date: 2026-09-12

Organizations using Check Point VPN infrastructure are facing an urgent remediation task after the Dutch National Cyber Security Centre warned that two critical vulnerabilities could soon attract exploitation attempts. The flaws, tracked as CVE-2026-85102 and CVE-2026-85103, affect components involved in VPN negotiation and certificate processing.

A Gateway-Level Security Risk

CVE-2026-85102 involves improper validation of certificate data during VPN negotiation. A remote attacker could potentially exploit the weakness to execute arbitrary code on a Security Gateway. CVE-2026-85103 is a heap overflow in the ASN.1 certificate decoder and can also lead to remote code execution on gateways and management servers.

The location of these vulnerabilities is particularly concerning. VPN gateways are commonly exposed to the internet and are trusted to provide authenticated access to internal networks. If an attacker compromises that boundary device, the incident can quickly become more serious than the loss of a single endpoint. The intruder may be able to inspect traffic, steal configuration data, disrupt remote access or use the gateway as a foothold for lateral movement.

What Administrators Should Do

  • Install Check Point LivePatch Take 24 where it is supported.
  • Upgrade systems to the applicable Jumbo Hotfix Accumulator or corrected Spark release.
  • Confirm that automatic LivePatch protection was successfully applied rather than assuming it is active.
  • Restrict site-to-site VPN rules to known and trusted IP addresses wherever operationally possible.
  • Identify unsupported R80 and R81 installations and prioritize their replacement.
  • Review gateway and management logs for unusual certificate-processing failures, crashes and configuration changes.

Check Point R82.20 is not affected, but several widely deployed R81 and R82 releases require updates. Systems running end-of-support versions face an additional problem because they may lack a straightforward or sustainable remediation path.

Expert View

In my view, organizations should treat this warning as a pre-exploitation alert rather than wait for confirmed attacks. Internet-facing security appliances are frequently scanned soon after technical details become available, and a VPN gateway offers attackers a strategically valuable position. Applying the fix is the immediate priority, but defenders should also verify exposure, investigate suspicious activity and ensure that administrative interfaces cannot be reached from untrusted networks.

Talk to our team →

Latest

Phishing Study Finds Click Rates Are Hiding the Metrics That Actually MatterSep 14, 2026Claude Distillation Campaigns Turn AI Access Into an Industrial Data-Theft MarketSep 14, 2026Check Point VPN Flaws Put Enterprise Gateways on an Urgent Patch ClockSep 14, 2026Microsoft Maps the Hidden Attack Paths Connecting Serverless Apps to Cloud ControlSep 13, 2026Brevo Breach Turns Trusted Trezor Emails Into Wallet-Stealing PhishingSep 13, 2026Cisco Firewall Manager Flaws Become Launchpads for Espionage and Qilin RansomwareSep 13, 2026

Most read

1Microsoft Redraws the Security Boundary for Edge AI2Ted Implant Turns Compromised HAProxy Servers Into Invisible Interception Points3French Hospital Fine Turns Weak Identity Controls Into a GDPR Warning4IDScan Lawsuits Put Mass Identity Collection Under the Microscope5Scattered Spider's Cyberattack on Marks & Spencer Exposes Retail Vulnerabilities6Microsoft Prepares Windows Customers for a Faster Era of AI-Driven Patching