INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Dutch NCSC Warns of Critical Check Point VPN Flaws
| 2026-09-12 14:14 CRITICAL HIGHExecutive Summary AI-generated
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN, tracked as CVE-2026-85102 and CVE-2026-85103. These vulnerabilities have been identified by a remote attacker who could exploit them to execute arbitrary code on Security Gateways and Management Servers. The NCSC advises organizations to install security updates addressing the issues immediately, citing no public proof-of-concept exploits despite this. Check Point has issued fixes for both flaws along with separate advisories describing them, including CVSS scores of 9.8. Affected releases include R81.20, R82, and R82.10, while additional versions are available through LivePatch Take 24 or later. Organizations must modify VPN rules to limit access to specific trusted IP addresses for those using the 'Site-to-Site VPN' component.
Technical Mitigations AI-generated
* Implement a VPN rule modification to limit access to specific, trusted IP addresses for the "Site-to-Site VPN" component of Check Point VPN.
* Run the latest version of Check Point LivePatch Take 24 or later on R81.20, R82, and R82.10 to fix CVE-2026-85102 and Jumbo Hotfix Accumulator Take 44 or later on R82.
* Use a secure communication protocol such as TLS 1.2 or higher for all VPN connections to prevent exploitation of the heap-based buffer overflow vulnerability (CVE-2026-85103).
* Regularly update and patch Check Point's firewall and management products, including Security Gateways, firewalls appliances, Quantum Security Management systems, and Quantum Security Gateway systems, with the latest security updates.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SparkSpark
CVE-2026-85103CVE-2026-85103
CVE-2026-85102CVE-2026-85102
CVE-2026-50751CVE-2026-50751
CVE-2026-16232CVE-2026-16232
Target & Sectors
Global Scope
Incident Timeline
June 8
Threat actors are expected to exploit known vulnerabilities in Dutch National Cyber Security Centre's Check Point VPN by June 8.
Click on any entity below to view its context and source!
attribution
Known Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalog on June 8.
tactic
T1588.006 - Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalog on June 8.
September 1
Threat actors exploited vulnerabilities in Dutch National Cyber Security Centre's (NCSC) Critical Check Point VPN software by installing the vulnerable version on September 1.
Click on any entity below to view its context and source!
general_metric
18 Take
Five separate accounts reported gateways were still on Take 18 or Take 17 of the urgent security update package on the day of the announcement; one of them posted an update log showing Take 18 installed on September 1 and nothing since.
September 9
Threat actors exploited vulnerabilities in Check Point's Live Patch (CPLP) to gain unauthorized access.
Click on any entity below to view its context and source!
organisation
Check Point
On September 9, Check Point issued fixes for the flaws along with separate security advisories describing them:
sk1000117
and
sk1000118
.
Check Point disclosed the flaws on September 9 in a
notice to its customer community
, and began delivering fixes the same day.
2026/09/12
Check Point patched two critical flaws in its VPN software that could allow remote code execution on Security Gateways and Security Management Servers.
Click on any entity below to view its context and source!
organisation
The Dutch Nationaal Cyber Security Centrum
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
organisation
NCSC
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
organisation
Check Point VPN
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
organisation
CVE-2026
CVE-2026-85102 is an improper validation of certificate data during VPN negotiation that a remote attacker could exploit to execute arbitrary code on a Security Gateway.
In the same community thread, a Check Point staff member was asked whether gateways with the VPN software blade turned off are affected by CVE-2026-85103.
organisation
Security Gateways and Security Management Servers
CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder that could allow remote code execution on Security Gateways and Security Management Servers.
infrastructure
00.10
R82.10 Jumbo Hotfix Accumulator Take 44 or later
R82 Jumbo Hotfix Accumulator Take 126 or later
R81.20 Jumbo Hotfix Accumulator Take 166 or later
Spark R82.00.10 Build 2325 or later
Spark R81.10.17 Build 4968 or later
Check Point VPN version R82.20 is not affected by either flaw.
infrastructure
10.17
R82.10 Jumbo Hotfix Accumulator Take 44 or later
R82 Jumbo Hotfix Accumulator Take 126 or later
R81.20 Jumbo Hotfix Accumulator Take 166 or later
Spark R82.00.10 Build 2325 or later
Spark R81.10.17 Build 4968 or later
Check Point VPN version R82.20 is not affected by either flaw.
organisation
Jumbo Hotfix
R82.10 Jumbo Hotfix Accumulator Take 44 or later
R82 Jumbo Hotfix Accumulator Take 126 or later
R81.20 Jumbo Hotfix Accumulator Take 166 or later
Spark R82.00.10 Build 2325 or later
Spark R81.10.17 Build 4968 or later
Check Point VPN version R82.20 is not affected by either flaw.
organisation
Security Management
Neither Check Point's notice nor any public record reviewed for this article states which Spark or Security Management versions are affected, which builds contain the fix, or what specific conditions the company says the flaws require.
organisation
PoC
Although no public proof-of-concept (PoC) exploit has been reported, the agency is urging organizations to install the security updates addressing the two issues as soon as possible.
organisation
EoS
Affected releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, along with the end-of-support (EoS) versions R80 through R80.40, R81, and R81.10.
organisation
R81
Affected releases include R81.20, R82, R82.10, R81.10.x, and R82.00.x, along with the end-of-support (EoS) versions R80 through R80.40, R81, and R81.10.
organisation
Check Point LivePatch Take
Both flaws are fixed by Check Point LivePatch Take 24 for R81.20, R82, and R82.10, while fixes are also included in the following versions:
organisation
IP
At the same time, for those using the ‘Site-to-Site VPN’ component, the advice is to modify VPN rules to limit access to specific, trusted IP addresses.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CVSS
Both records carry a CVSS score of 9.8.
organisation
Remote Access VPN
June's was
CVE-2026-50751
, an authentication bypass in Remote Access VPN and Mobile Access certificate validation.
organisation
Mobile Access
June's was
CVE-2026-50751
, an authentication bypass in Remote Access VPN and Mobile Access certificate validation.
organisation
the Security Management
The other affects those gateways and the Security Management Server, the console used to configure them.
organisation
Check Point's
One flaw affects Check Point's Security Gateways, its firewall appliances.
organisation
Security Gateways
One flaw affects Check Point's Security Gateways, its firewall appliances.
organisation
Quantum Security Management
Its record says an unauthenticated remote attacker may be able to run code on Quantum Security Management and Quantum Security Gateway systems.
organisation
Quantum Security Gateway
Its record says an unauthenticated remote attacker may be able to run code on Quantum Security Management and Quantum Security Gateway systems.
organisation
Quantum
The list covers three Quantum branches and gives no version information for anything else.
organisation
the Canadian Center for Cyber Security
An
advisory from the Canadian Center for Cyber Security
, published the same evening, lists a broader set of products but no versions at all.
organisation
R82.00
A Check Point employee said in the thread that it can be installed on top of any Jumbo Hotfix level in R81.20, R82.00 and R82.10, and named only those three versions.
Tactical Metrics
Metrics
infrastructure
00.10
Software Version
Click for context!
R82.10 Jumbo Hotfix Accumulator Take 44 or later
R82 Jumbo Hotfix Accumulator Take 126 or later
R81.20 Jumbo Hotfix Accumulator Take 166 or later
Spark R82.00.10 Build 2325 or later
Spark R81.10.17 Build 4968 or later
Check Point VPN version R82.20 is not affected by either flaw.
Metrics
infrastructure
10.17
Software Version
R82.10 Jumbo Hotfix Accumulator Take 44 or later
R82 Jumbo Hotfix Accumulator Take 126 or later
R81.20 Jumbo Hotfix Accumulator Take 166 or later
Spark R82.00.10 Build 2325 or later
Spark R81.10.17 Build 4968 or later
Check Point VPN version R82.20 is not affected by either flaw.
Intelligence Sources
The Hacker News
2026-09-10
BleepingComputer
2026-09-12
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-13T06:00
Comprehensive Tactical Telemetry
Highly Correlated Entities
26x
organisation
Identified Entity
The Dutch Nationaal Cyber Security Centrum
entity
5x
timeline
Temporal Reference
44 or later
date
4x
vulnerability
Exploited CVE
CVE-2026-85102
cve
4x
attribution
Attributing Entity
SmartConsole
authority
2x
tactic
Cyber Operation Type
Remote Code Execution
tactic
2x
infrastructure
Software Version
00.10
version
2x
general metric
Accumulator
126
accumulator
2x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
2x
general metric
Hotfix
125
hotfix
Contextual Telemetry
Context Block
4 METRICS
malware
Malware Payload
Spark
tool
vulnerability
CVSS Score
10
score
general metric
Take
18
take
general metric
Point
10
point
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.