Dutch NCSC Warns Check Point VPN Exploitation Imminent
Dutch NCSC warns exploitation of two CVSS 9.8 Check Point VPN RCE flaws is imminent. If you haven't patched CVE-2026-85102 and CVE-2026-85103, do it now.

The Dutch Nationaal Cyber Security Centrum (NCSC) said on September 12 that exploitation of CVE-2026-85102 and CVE-2026-85103 is imminent. Both are CVSS 9.8 unauthenticated remote code execution flaws in Check Point firewall and management products. Patches have been available since September 10. If you haven’t applied them yet, this moves to emergency priority now.
BleepingComputer reported the NCSC advisory. The center’s assessment is that exploitation has not been confirmed in the wild yet, but is likely to begin soon given the severity of the flaws and the technical details now in circulation.
Both CVEs sit in how Check Point appliances process VPN certificates. No credentials, no user interaction required: a network-accessible attacker can execute code on the appliance. CVSS 9.8 on each.
What to do now
Check Check Point’s support portal for the patch build that covers your specific product branch and apply it. If patching is not possible immediately, restrict management interface access to known administrative source IPs to cut off the exposed attack surface.
The NCSC warning is not the only reason to move fast. Check Point products have been a consistent exploitation target. In July 2026, a PoC for CVE-2026-16232, an admin-bypass flaw in SmartConsole, was public within two weeks of the patch and earned a CISA KEV listing quickly. Neither CVE-2026-85102 nor CVE-2026-85103 is on CISA’s Known Exploited Vulnerabilities catalog at time of writing. Given Check Point’s track record, patch before that changes, not after.
- [ CRITICAL ]CVE-2026-85102Unauthenticated RCE via VPN certificate handling in Check Point products
- [ CRITICAL ]CVE-2026-85103Unauthenticated RCE via VPN certificate handling in Check Point products
Found this useful? Share it.


