Vulnerability
Published 2026-09-09
Verified 2026-09-19

Check Point VPN CVE-2026-85102/85103 (CVSS 9.8); Dutch NCSC: exploitation imminent

Check Point support articles sk1000117 and sk1000118 (disclosed 9 September 2026) cover two critical VPN-certificate handling flaws the vendor found internally. CVE-2026-85102 (sk1000117) is authentication bypass and remote code execution in Remote Access and Site-to-Site VPN on Quantum Security Gateway when certificate trust is not validated correctly during VPN negotiation. CVE-2026-85103 (sk1000118) is a heap-based buffer overflow while decoding the ASN.1 structure of a VPN certificate that can yield unauthenticated RCE on Quantum Security Gateway and Quantum Security Management. Both carry CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) per the CVE records. Vendor reporting at disclosure said no evidence of in-the-wild use. UPDATE 12 September 2026: the Dutch NCSC (alert) assesses likelihood of exploitation and potential impact as high and expects exploitation attempts soon; no public PoC reported at that writing. NCSC urges immediate updates and, for Site-to-Site VPN, limiting peers to trusted IPs. LivePatch Take 24 / matching Jumbo builds as in the SK articles; R82.20 unaffected. Affected Jumbo trains cited in public writeups include R82.10 Take 43 or below, R82 Take 125 or below, and R81.20 Take 165 or below (plus older EOS trains in third-party summaries); R82.20 called unaffected. Apply the matching Jumbo Hotfix / LivePatch from the SK articles. Primary: Check Point sk1000117; also sk1000118; wire: The Hacker News (10 Sep 2026).

Product
Check Point Quantum Security Gateway / Quantum Security Management (VPN certificate handling)
Versions
Public writeups: R82.10 Jumbo Take ≤43; R82 Jumbo Take ≤125; R81.20 Jumbo Take ≤165 (and older EOS trains); R82.20 unaffected — confirm on sk1000117/sk1000118
CVSS
(CVE-2026-85102 and CVE-2026-85103, CVSS 3.1)
Exploited in Australia?
unknown
Patch to
Apply Check Point Jumbo Hotfix / LivePatch per sk1000117 and sk1000118 for your train

Primary: Check Point sk1000117 — CVE-2026-85102 · Vendor: Check Point sk1000118 — CVE-2026-85103 · CVE: CVE-2026-85102, CVE-2026-85103 · Dutch NCSC alert — imminent exploitation expected (12 Sep 2026); also THN/BC

vulnerabilities network