INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Dutch NCSC Warns of Critical Check Point VPN Flaws

| 2026-09-12 14:14 CRITICAL HIGH
Executive Summary AI-generated
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN, tracked as CVE-2026-85102 and CVE-2026-85103. These vulnerabilities have been identified by a remote attacker who could exploit them to execute arbitrary code on Security Gateways and Management Servers. The NCSC advises organizations to install security updates addressing the issues immediately, citing no public proof-of-concept exploits despite this. Check Point has issued fixes for both flaws along with separate advisories describing them, including CVSS scores of 9.8. Affected releases include R81.20, R82, and R82.10, while additional versions are available through LivePatch Take 24 or later. Organizations must modify VPN rules to limit access to specific trusted IP addresses for those using the 'Site-to-Site VPN' component.
Technical Mitigations AI-generated
* Implement a VPN rule modification to limit access to specific, trusted IP addresses for the "Site-to-Site VPN" component of Check Point VPN. * Run the latest version of Check Point LivePatch Take 24 or later on R81.20, R82, and R82.10 to fix CVE-2026-85102 and Jumbo Hotfix Accumulator Take 44 or later on R82. * Use a secure communication protocol such as TLS 1.2 or higher for all VPN connections to prevent exploitation of the heap-based buffer overflow vulnerability (CVE-2026-85103). * Regularly update and patch Check Point's firewall and management products, including Security Gateways, firewalls appliances, Quantum Security Management systems, and Quantum Security Gateway systems, with the latest security updates.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SparkSpark CVE-2026-85103CVE-2026-85103 CVE-2026-85102CVE-2026-85102 CVE-2026-50751CVE-2026-50751 CVE-2026-16232CVE-2026-16232
Target & Sectors
Global Scope
Incident Timeline
‎June 8
Threat actors are expected to exploit known vulnerabilities in Dutch National Cyber Security Centre's Check Point VPN by June 8.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
‎September 1
Threat actors exploited vulnerabilities in Dutch National Cyber Security Centre's (NCSC) Critical Check Point VPN software by installing the vulnerable version on September 1.
general_metric 18 Take
‎September 9
Threat actors exploited vulnerabilities in Check Point's Live Patch (CPLP) to gain unauthorized access.
organisation Check Point
‎2026/09/12
Check Point patched two critical flaws in its VPN software that could allow remote code execution on Security Gateways and Security Management Servers.
organisation The Dutch Nationaal Cyber Security Centrum
organisation NCSC
organisation Check Point VPN
organisation CVE-2026
organisation Security Gateways and Security Management Servers
infrastructure 00.10
infrastructure 10.17
organisation Jumbo Hotfix
organisation Security Management
organisation PoC
organisation EoS
organisation R81
organisation Check Point LivePatch Take
organisation IP
organisation NFL
organisation CHANEL
organisation CVSS
organisation Remote Access VPN
organisation Mobile Access
organisation the Security Management
organisation Check Point's
organisation Security Gateways
organisation Quantum Security Management
organisation Quantum Security Gateway
organisation Quantum
organisation the Canadian Center for Cyber Security
organisation R82.00
Tactical Metrics
Metrics
infrastructure
‎00.10
Software Version
Metrics
infrastructure
‎10.17
Software Version
Intelligence Sources