Check Point VPN CVE-2026-85102/85103 (CVSS 9.8); Dutch NCSC: exploitation imminent
Check Point support articles sk1000117 and sk1000118 (disclosed 9 September 2026) cover two critical VPN-certificate handling flaws the vendor found internally. CVE-2026-85102 (sk1000117) is authentication bypass and remote code execution in Remote Access and Site-to-Site VPN on Quantum Security Gateway when certificate trust is not validated correctly during VPN negotiation. CVE-2026-85103 (sk1000118) is a heap-based buffer overflow while decoding the ASN.1 structure of a VPN certificate that can yield unauthenticated RCE on Quantum Security Gateway and Quantum Security Management. Both carry CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) per the CVE records. Vendor reporting at disclosure said no evidence of in-the-wild use. UPDATE 12 September 2026: the Dutch NCSC (alert) assesses likelihood of exploitation and potential impact as high and expects exploitation attempts soon; no public PoC reported at that writing. NCSC urges immediate updates and, for Site-to-Site VPN, limiting peers to trusted IPs. LivePatch Take 24 / matching Jumbo builds as in the SK articles; R82.20 unaffected. Affected Jumbo trains cited in public writeups include R82.10 Take 43 or below, R82 Take 125 or below, and R81.20 Take 165 or below (plus older EOS trains in third-party summaries); R82.20 called unaffected. Apply the matching Jumbo Hotfix / LivePatch from the SK articles. Primary: Check Point sk1000117; also sk1000118; wire: The Hacker News (10 Sep 2026).
- Product
- Check Point Quantum Security Gateway / Quantum Security Management (VPN certificate handling)
- Versions
- Public writeups: R82.10 Jumbo Take ≤43; R82 Jumbo Take ≤125; R81.20 Jumbo Take ≤165 (and older EOS trains); R82.20 unaffected — confirm on sk1000117/sk1000118
- CVSS
- (CVE-2026-85102 and CVE-2026-85103, CVSS 3.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Apply Check Point Jumbo Hotfix / LivePatch per sk1000117 and sk1000118 for your train
Primary: Check Point sk1000117 — CVE-2026-85102 · Vendor: Check Point sk1000118 — CVE-2026-85103 · CVE: CVE-2026-85102, CVE-2026-85103 · Dutch NCSC alert — imminent exploitation expected (12 Sep 2026); also THN/BC
