Dutch agency warns of imminent attacks on Check Point VPN vulnerabilities

The Dutch National Cyber Security Centre has issued an urgent warning about two critical flaws in Check Point VPN products, predicting exploitation attempts in the near term. The vulnerabilities, tracked as CVE-2026-85102 and CVE-2026-85103, could allow remote code execution on Security Gateways and Management Servers. Administrators are advised to apply the available patches immediately and restrict VPN access to trusted IP addresses where possible.
The two vulnerabilities affect a broad range of Check Point releases, including versions that have reached end-of-support status, meaning some organizations may need to upgrade rather than simply patch. Check Point has distributed fixes through multiple channels, with LivePatch covering newer releases and Jumbo Hotfix Accumulators for others, while the R82.20 version remains unaffected.
The NCSC's warning arrives despite no public proof-of-concept being available, reflecting the agency's assessment that the flaws' severity and the value of VPN infrastructure as an attack target make exploitation highly probable. Administrators using Site-to-Site VPN are advised to restrict access to trusted IP addresses as an interim measure while patches are deployed.
Organizations relying on Check Point VPN for remote workforce connectivity could face significant operational disruption if these flaws are exploited, potentially exposing confidential data or enabling full system takeovers. Government agencies, enterprises, and managed service providers using affected versions may be particularly vulnerable, especially those still running end-of-support releases. The broader impact could extend to employees and customers whose personal information resides on compromised networks. While patches are available, the window between warning and exploitation may be narrow, and organizations without robust update processes could find themselves exposed.