CVE Tools
Back to feed
Advisory Check Point VPN network-edge Security Gateway Check Point zero-day

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

BleepingComputer·By Bill Toulas··2 min read
CVE Tools coverage

The Dutch NCSC has issued an urgent alert regarding the likely immediate exploitation of two critical vulnerabilities in Check Point VPN, specifically CVE-2026-85102 and CVE-2026-85103. These flaws permit remote attackers to gain control of Security Gateway and Security Management Server components by exploiting improper certificate validation and a heap overflow in the ASN.1 decoder. Although no public exploit code is currently available, the agency recommends applying security updates immediately to mitigate the risk of data theft and operational disruption.