The National Cyber Security Centre warns on 10 September 2026 for two critical vulnerabilities in Check Point VPN products:

  • CVE-2026-85102
  • CVE-2026-85103

Both have a CVSS score of 9.8 and can be under affected configurations by an external attacker without valid login data are being exploited to execute arbitrary code.

The NCSC assesses both the risk of abuse and potential damage as well as high and expects that rapid attempts at widespread abuse will follow.

Check Point has made security updates available.

Are you using Check Point VPN or Quantum Security Gateway? Then check today if you are using an affected version and install the required update.

Is there any active abuse?

No public Proof-of-Concept or Exploit Code was reported on 10 September 2026. However, the NCSC expected large-scale abuses to follow in the short term. Check Point itself indicated no evidence of active operation to have.

There was therefore no confirmed active abuse at that time. The severity, external accessibility and available updates made quick action necessary.

What do the two vulnerabilities do?

CVE-2026-85102

The vulnerability affects certificate and trust validation during VPN negotiation in Check Point Quantum Security Gateway. Under affected conditions, an unauthenticated remote attacker can execute arbitrary code on the gateway.

CVE-2026-85103

A heap-based buffer overflow in the ASN.1 processing of VPN certificates can also lead to remote code execution without prior authentication.

Which versions are vulnerable?

The exact impact depends on product and software branch.

The CVE records include vulnerable branches such as:

  • R82.10 with older Jumbo Hotfix Takes;
  • R82 with older Jumbo Hotfix Takes;
  • R81.20 with older Jumbo Hotfix Takes.

The branches mentioned are examples and do not form a complete patch matrix. For current status, always consult the official Check Point security advice.

Check Point advises the latest relevant Jumbo Hotfix install as soon as possible.

For customers using Check Point Live Patch, protection has been rolled out according to Check Point from 9 September.

Why is VPN vulnerability important?

A VPN gateway is designed to allow trusted external access to an organisation.

A vulnerability that allows an attacker to execute code without authentication is thus touching a system that is on the edge of the network.

A compromised gateway can provide an input to internal systems, network traffic, accounts, management functions and confidential information depending on architecture and follow-up steps.

What do you have to do now?

1. Check if you are using Check Point VPN

Check product, software version and used VPN features.

2. Install the current Check Point update

Follow the security advice and Jumbo Hotfix that you have to release.

3. Check Site-to-Site VPN rules

The NCSC also advises organisations to assess the configuration measures described by Check Point with Site-to-Site VPN, including limiting VPN access and disabling implied rules where appropriate.

4. Check Internet exposure and management

Ensure that management interfaces are not unnecessarily accessible to the public and limit access sources where possible.

5. Do not wait until public abuse is confirmed

The vulnerabilities are relevant because a patch is available before wide active abuse has been confirmed.

The wider lesson

The safest patch is often the patch that is installed before attackers start large-scale scanning.

But to do that, you need to know what equipment you use, what version runs on it, which systems are internet-facing, who assesses advice, how quickly an update can be performed and how you check that the update is actually installed. Read how to organize this structuralally with vulnerability management and patch management.

What can you check directly?

Are you using Check Point VPN products?

  • Check product and software version immediately.
  • Compare the surroundings with the current Check Point advisories.
  • Install the relevant Jumbo Hotfix/update.
  • Review additional Site-to-Sitemitigations.
  • Have an external IT partner prove to confirm what has been checked and updated.

Sources and deepening

Based on official frameworks and practical implementation

The source pages provide the formal background. Kynexis Information Security translates this information into an executable approach for your organisation, sector and risk profile.

View NCSC - Critical vulnerabilities in Check Point VPN productsView Check Point - CVE-2026-85102View Check Point - CVE-2026-85103