โ Back to Feed
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
CVE-2026-85102CVE-2026-85103
September 12, 2026 ยท BleepingComputer ยท Severity: CRITICAL
The Dutch NCSC has issued an urgent warning regarding two critical vulnerabilities in Check Point VPN products, stating that exploitation is imminent. CVE-2026-85102 and CVE-2026-85103 allow remote attackers to compromise VPN gateways and gain unauthorized network access. ๐ **Analyst Note:** This is a textbook example of why VPN appliances remain one of the highest-risk assets in any network โ they sit at the network perimeter with privileged access, and a single unpatched critical flaw can undo years of defense-in-depth investment.
Key Takeaways
- The Dutch NCSC has issued a formal warning that CVE-2026-85102 and CVE-2026-85103 are likely to see imminent exploitation, urging all organizations using Check Point VPN products to prioritize patching.
- Both vulnerabilities allow remote attackers to compromise VPN gateways without authentication, potentially granting complete network access to internal corporate environments.
- Given the critical severity and the NCSC's active threat assessment, security teams should treat this as an active emergency patching situation requiring immediate action.