Key Facts
The Dutch NCSC warns of two critical Check Point VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, and assesses both the likelihood and potential damage of exploitation as high.
Technical Details
Security Affairs reports that the flaws affect VPN negotiation and certificate ASN.1 decoding and may permit unauthenticated remote code execution. The NCSC alert says exploitation is expected; it does not report confirmed active exploitation.
Impact & Mitigation
Apply the vendor updates promptly. The NCSC also recommends restricting site-to-site VPN access to trusted IP addresses and disabling implied rules where appropriate.
