CVE-2026-85102 & CVE-2026-85103 (CVSS 9.8): Dutch NCSC Warns Check Point VPN Firewalls Face Imminent Pre-Auth RCE — Patch Now
If your organisation runs Check Point Security Gateway, Security Management Server, or Spark Firewall, this is the alert you cannot afford to ignore this week. On 9 September 2026, Check Point quietly pushed emergency LivePatch Take 24 to address two freshly discovered critical vulnerabilities — CVE-2026-85102 and CVE-2026-85103, both rated CVSS 9.8. Both allow a completely unauthenticated remote attacker to achieve arbitrary code execution on your perimeter security devices, with no user interaction required. Now the Dutch National Cyber Security Centre (NCSC) has escalated its posture, declaring that exploitation is imminent and urging every affected organisation worldwide to patch immediately. The window between “no known exploit” and “actively weaponised” is collapsing, and with enterprise perimeter firewalls in the crosshairs, the blast radius is existential.
- CVE-2026-85102 (CVSS 9.8): Improper certificate validation in VPN negotiation enables unauthenticated RCE on Check Point Security Gateways and Spark Firewalls using Site-to-Site or Remote Access VPN.
- CVE-2026-85103 (CVSS 9.8): Heap overflow in VPN certificate ASN.1 decoding leads to unauthenticated RCE on Security Management Servers, Security Gateways, and Spark Firewalls.
- Affected Jumbo Hotfix builds: R82.10 Take 43 and below; R82 Take 125 and below; R81.20 Take 165 and below. End-of-life versions (R80.40, R81, R81.10) also vulnerable.
- R82.20 is not affected.
- Temporary mitigation via LivePatch Take 24 (available since 9 September 2026); permanent fix via Jumbo Hotfix Accumulator R82.10 Take 44 / R82 Take 126 / R81.20 Take 166.
- The Dutch NCSC assesses exploitation likelihood and impact as high and expects active exploitation soon — no public PoC yet, but that window is closing.
- Check Point’s own security research team discovered both flaws; no evidence of active exploitation at time of writing.
The Vulnerability Pair: Two Critical Flaws in the Same Attack Surface
Both CVE-2026-85102 and CVE-2026-85103 live in the VPN certificate processing stack — the very code that handles cryptographic handshakes when remote users or branch offices connect to your gateway. That’s not a coincidence; it’s a sign that Check Point’s internal research team ran a deep audit on this component after discovering the first flaw.
CVE-2026-85102 stems from improper validation of certificate data during VPN negotiation. When a client initiates a VPN session — whether Site-to-Site or Remote Access — the gateway parses certificate fields before verifying the identity of the connecting party. By sending a specially crafted certificate, an attacker who has never authenticated can manipulate this parsing step to overwrite memory and gain code execution running with gateway-level privileges. In a typical deployment, the gateway is reachable directly from the internet; there is no “inside the perimeter” requirement.
CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoding flow. ASN.1 (Abstract Syntax Notation One) is the encoding standard used for X.509 certificates. Parsing ASN.1 is notoriously tricky, and even well-maintained TLS stacks have suffered heap overflows here (Heartbleed used a related primitive). The Check Point flaw allows an oversized or malformed ASN.1 structure to overflow the heap, giving an attacker a powerful primitive that can be developed into reliable remote code execution. Critically, CVE-2026-85103 also affects the Security Management Server — the “brain” of a Check Point estate — potentially allowing an attacker to pivot to every managed gateway.
Together, these two flaws represent a worst-case scenario: a one-two punch against the most sensitive devices in an enterprise’s network perimeter. Both bugs require zero authentication, zero user interaction.
Technical Breakdown: Affected Products and Version Matrix
Check Point has published a clear version matrix. Before you do anything else, establish which Jumbo Hotfix Take your gateways and management servers are running.
| Product / Version | Vulnerable Take | Fixed Take | CVE(s) |
|---|---|---|---|
| Security Gateway / Spark Firewall — R82.10 | Take 43 and below | Take 44+ | 85102, 85103 |
| Security Gateway / Spark Firewall — R82 | Take 125 and below | Take 126+ | 85102, 85103 |
| Security Gateway / Spark Firewall — R81.20 | Take 165 and below | Take 166+ | 85102, 85103 |
| Security Management Server (all above versions) | Same as gateway | Same fix take | 85103 only |
| EOL: R80.40, R81, R81.10 | All builds | No patch — upgrade required | 85102, 85103 |
| R82.20 | Not affected | — | — |
An interim LivePatch Take 24, distributed automatically since 9 September 2026, provides temporary protection by blocking the malformed certificate paths that trigger both bugs. However, a LivePatch is not a substitute for the full Jumbo Hotfix Accumulator update; live patches can be rolled back, may not survive gateway reboots in all configurations, and do not address the underlying code defect. Apply the full Jumbo HFA at the earliest maintenance window.
Why the Dutch NCSC Warning Changes Everything
Government cybersecurity agencies issue warnings constantly, but the Dutch NCSC’s language here is unusually direct. In its advisory, the centre writes: “The NCSC assesses the likelihood of exploitation and the potential impact as high and expects exploitation attempts to occur soon.” The Netherlands is home to a disproportionate share of global internet infrastructure — transit, cloud, financial services — and the Dutch NCSC has a strong track record of issuing pre-exploitation warnings that prove accurate within days.
The warning carries additional weight because the broader threat environment in September 2026 is saturated with perimeter-device exploitation. Earlier this month alone, Cisco Secure FMC vulnerabilities were weaponised by Sandworm and Qilin ransomware, and in late August, FortiGate firewalls were actively backdoored via the PivotC2 RAT. Nation-state threat actors and ransomware affiliates have made security gateways their primary initial-access vector because a compromised firewall gives an attacker everything — traffic visibility, lateral movement to all protected networks, and a persistent foothold that survives endpoint security tools entirely.
No public proof-of-concept (PoC) exploit has been published yet. That is the only thing standing between “imminent” and “active exploitation.” Once a working PoC appears on GitHub or exploit markets — historically a matter of days after a high-profile advisory — opportunistic scanning campaigns begin within hours. In 2026, this cycle is measurably faster than it was three years ago.
What You Should Do Right Now — Sanjay’s Zero-Trust Perspective
As a cybersecurity consultant who has architected Check Point and FortiGate deployments across banking, energy, and government sectors in the Delhi NCR region and beyond, here is my precise action checklist for every affected organisation:
- Inventory within the next four hours. Log into SmartConsole, run Gateway Status, and note the Jumbo Hotfix Take on every managed gateway and the management server. Cross-reference against the table above. If you are on an EOL version, escalate to your vendor immediately — there is no patch path short of a version upgrade.
- Verify LivePatch Take 24 is installed. On the management server, run
cpinfo -y allor check SmartConsole > Gateways > Summary > LiveUpdate. Confirm Take 24 is shown as installed and active. If it is not, trigger a manual LiveUpdate pull. - Schedule Jumbo HFA in the next 72 hours. Prioritise internet-facing gateways; management servers can follow immediately after. The full Jumbo HFA requires a gateway reboot; plan your change-management window now, not next month.
- Restrict VPN exposure at the perimeter. While awaiting the Jumbo HFA, review whether your VPN portals are exposed to the open internet unnecessarily. If you have regional offices, whitelist their public IP ranges on the gateway’s external interface — this does not fix the bug, but it dramatically reduces your attack surface.
- Enable IPS blade with Geo-Protection. Check Point’s IPS blade ships with protections that detect anomalous certificate handshakes. Ensure IPS is active on all internet-facing policies and that Geo-Protection is configured to drop traffic from high-risk autonomous systems if your business justifies it.
- Activate 24/7 alert monitoring on gateway logs. Instruct your SOC to watch for TLS negotiation failures, unusual ASN.1 parse error messages in gateway logs, and any unexpected outbound connections from the gateway’s management interface — all early indicators of a failed or successful exploitation attempt.
- If you are on R82.20 — confirm it. You should be unaffected, but verify by logging the running Jumbo Take. Do not rely on memory or a spreadsheet; verify it in the console.
- EOL version operators: treat this as a Code Red. R80.40, R81, and R81.10 receive no patch. Your only remediation path is upgrading to R81.20 or R82. If your platform does not support the newer version, contact Check Point reseller support for emergency upgrade licensing. This is not a “schedule for Q4” situation — this is a “activate the change-freeze waiver” situation.
From a zero-trust architecture standpoint, this incident underscores a principle I advocate in every engagement: your security gateway should itself be segmented. Management plane traffic (SmartConsole, logging) must never share an interface with data plane VPN traffic. If your management server is reachable from the same network segment as your VPN portal, a successful exploit of CVE-2026-85103 gives the attacker keys to every gateway in your estate simultaneously. Implement out-of-band management access if you have not done so.
Frequently Asked Questions
Are CVE-2026-85102 and CVE-2026-85103 being actively exploited right now?
As of 14 September 2026, Check Point confirms it has found no evidence of active exploitation and no public PoC has been released. However, the Dutch NCSC assesses exploitation as imminent, and the broader threat landscape — with perimeter devices being prioritised targets in 2026 — means this status can change within hours of a public PoC appearing. Treat this as an active incident and patch accordingly.
Does the LivePatch Take 24 fully protect me?
LivePatch Take 24 is an emergency temporary measure that blocks the specific exploit paths triggering both CVEs. It does significantly reduce your risk, but it is not a permanent fix, may not survive all reboot scenarios, and does not remediate the underlying code defect. The permanent fix is the full Jumbo Hotfix Accumulator update from Check Point’s official advisory.
I am running Check Point on Azure / AWS — am I affected?
Yes. Cloud-deployed Check Point Security Gateways running affected Jumbo Hotfix Takes are equally vulnerable. Confirm your cloud gateway’s running Take via SmartConsole and apply the Jumbo HFA just as you would for an on-premises appliance. The LivePatch mechanism is available for cloud deployments as well.
Should I disable VPN on my Check Point gateway until patched?
For most organisations, disabling VPN entirely is operationally impossible. Instead, implement compensating controls: restrict VPN portal exposure to known IP ranges, activate IPS protections, and expedite the patching window. If you are running a Managed Security Service (MSSP) arrangement, escalate to your provider immediately and request they treat this as a P1 patching event. If your organisation’s risk tolerance is extremely low and your VPN has low utilisation (for example, a DR gateway), temporarily disabling the VPN blade while the patch is applied is a valid option.
The Bigger Pattern — and What It Means for Indian Enterprises
India’s enterprise security market is heavily dependent on perimeter security platforms — Check Point deployments are widespread across BFSI, government PSUs, and critical infrastructure sectors in Delhi NCR, Mumbai, Bengaluru, and Hyderabad. A working exploit for these vulnerabilities would place thousands of Indian enterprises at direct risk of initial-access compromise, with the management server takeover vector (CVE-2026-85103) allowing a single successful intrusion to cascade across every protected network in a multi-branch estate.
CERT-In has not yet issued a specific advisory on CVE-2026-85102 and CVE-2026-85103, but given the Dutch NCSC’s posture, a CERT-In alert is likely within 24–48 hours. Do not wait for it — patch now, report after.
For further context on how perimeter-device vulnerabilities are being weaponised across the threat landscape in September 2026, see BleepingComputer’s coverage of the Dutch NCSC warning, SecurityWeek’s full technical breakdown, and the Check Point community advisory for the definitive version and hotfix guidance. Field Effect has also published a concise patch guide for security operations teams.
P J Networks provides rapid vulnerability assessment and emergency patching support for Check Point, FortiGate, and multi-vendor security gateway environments across India. If you are uncertain about your current Jumbo Hotfix Take or need urgent remediation guidance, contact Sanjay Seth today for a no-obligation security assessment. Do not let your perimeter become the front door for an adversary.