Back to advisories

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Two critical remote code execution vulnerabilities in Check Point VPN (CVE-2026-85102 and CVE-2026-85103) are facing imminent exploitation. Any organization running affected Check Point VPN appliances is at immediate risk of full system compromise. Unpatched instances are likely to be targeted within hours to days.

CRITICALAdvisorySep 14, 2026
Action required
Identify all Check Point VPN instances in your environment and patch to the latest security update immediately. If patching cannot be completed today, isolate affected VPN gateways from production networks pending remediation.
Affected products
Check Point VPNCheck PointSecurity GatewaySecurity Management ServerCheck Point LivePatch