Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Summary

The Dutch National Cyber Security Centre (NCSC) has issued a warning about the imminent exploitation of two critical vulnerabilities in Check Point VPN products. These flaws, tracked as CVE-2026-85102 and CVE-2026-85103, pose a significant risk to organizations relying on this VPN solution.

IFF Assessment

FOE

The discovery and imminent exploitation of critical vulnerabilities in a widely used VPN solution represent a significant threat to the security of organizations, making this bad news for defenders.

Severity

9.8 Critical

Defender Context

Defenders should prioritize patching or mitigating these identified Check Point VPN vulnerabilities immediately. The NCSC's warning of imminent exploitation suggests that attackers may already be developing or actively using exploits for these flaws. Organizations need to review their network perimeter security and ensure all VPN appliances are updated to the latest secure versions.

Read Full Story →