Advisory Check Point VPN network-edge Security Gateway Check Point zero-day
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
CVE Tools coverage
The Dutch NCSC has issued an urgent alert regarding the likely immediate exploitation of two critical vulnerabilities in Check Point VPN, specifically CVE-2026-85102 and CVE-2026-85103. These flaws permit remote attackers to gain control of Security Gateway and Security Management Server components by exploiting improper certificate validation and a heap overflow in the ASN.1 decoder. Although no public exploit code is currently available, the agency recommends applying security updates immediately to mitigate the risk of data theft and operational disruption.