The Dutch National Cyber Security Centre (NCSC) has issued a rare pre-emptive warning: two critical flaws in Check Point VPN products, patched only days ago, are expected to see large-scale attacks "soon" — even though no working exploit code is public yet. Both bugs carry a 9.8 out of 10 severity score and need no login at all to trigger.
CVE-2026-85102 lets an attacker abuse a certificate-trust flaw during VPN negotiation to impersonate a trusted party. CVE-2026-85103 is a heap overflow in how the same VPN component decodes certificates, which can lead to full remote code execution. Together they affect Check Point Security Gateways, Spark Firewalls, and — for the heap overflow — the Security Management Server itself, across the R81.x and R82.x product lines (R82.20 is not affected). Check Point shipped fixes on 9 September 2026; the NCSC's warning followed three days later, citing the combination of no authentication required, high potential impact, and VPN gateways' status as an internet-facing front door as reasons it expects "large-scale abuse" imminently.
What this means for your business
If a Check Point VPN gateway sits between the internet and your office network, treat the patch as due now, not on the next maintenance window — the whole point of the NCSC's warning is that the gap between "patch available" and "mass exploitation" is closing faster than usual, because both flaws are unauthenticated and the products are easy to find by internet-wide scanning. Confirm with whoever manages your firewall (in-house IT or an outsourced provider) that Check Point's LivePatch or the full update has actually been applied, not merely scheduled, and that Site-to-Site VPN access is restricted to known IP ranges where your setup allows it. If you're not certain who manages your VPN gateway or whether it runs an affected version, that uncertainty is itself the thing to resolve this week, before an attacker resolves it for you.