TTO-2026-0913-123 · September 13, 2026 Active ExploitationCritical

Check Point VPN CVE-2026-85102 and CVE-2026-85103 CVSS 9.8 Draw Imminent Exploitation Warning from Dutch NCSC

checkpoint.comCVE-2026-85102 CVSS 9.8CVE-2026-85103Dutch NCSC imminent exploitation warningUnauthenticated RCEIPSec VPN gateway

Summary

The Dutch National Cyber Security Centre issued an imminent exploitation warning on September 12, 2026 for two critical vulnerabilities in Check Point Network Security gateways: CVE-2026-85102 and CVE-2026-85103. Both vulnerabilities carry a CVSS score of 9.8 and affect the IPSec VPN and SSL VPN components of Check Point’s Quantum Security Gateway and CloudGuard Network products. CVE-2026-85102 allows an unauthenticated remote attacker to execute arbitrary code on the gateway; CVE-2026-85103 allows memory disclosure that can be chained to improve exploitation reliability. Check Point released patches on September 10, 2026. The Dutch NCSC’s imminent warning reflects intelligence that exploitation is being actively prepared or has begun against unpatched internet-facing gateways.

Timeline

DateEvent
Sep 10, 2026Check Point releases patches for CVE-2026-85102 and CVE-2026-85103 affecting Quantum Security Gateway and CloudGuard Network
Sep 11, 2026Proof-of-concept code for CVE-2026-85102 circulates in private channels
Sep 12, 2026Dutch NCSC issues imminent exploitation warning; advises immediate patching of all internet-facing Check Point gateways
Sep 13, 2026Active scanning for vulnerable Check Point gateways observed across multiple threat intelligence feeds

What Happened

CVE-2026-85102 is a stack buffer overflow in Check Point’s IKE daemon, the component that handles IPSec VPN key negotiation. An unauthenticated attacker with network access to the gateway can send a malformed IKE packet that triggers the overflow and achieves remote code execution as root on the underlying operating system. No authentication, credentials, or prior access are required. CVE-2026-85103 is a separate memory disclosure vulnerability in the SSL VPN component that leaks heap contents, allowing an attacker to defeat ASLR and significantly increase the reliability of CVE-2026-85102 exploitation when chained.

Check Point Security Gateways are perimeter devices protecting corporate networks. Successful exploitation gives an attacker a root shell on the firewall itself — the network boundary device — with full visibility into traffic flowing through it, the ability to modify firewall rules, and a pivot point into the internal network behind it. The Dutch NCSC’s imminent warning indicates that exploitation has been observed or is credibly anticipated against Dutch government and critical infrastructure networks, consistent with a pattern of VPN gateway exploitation by state-sponsored actors throughout 2025 and 2026.

Affected products include Quantum Security Gateway R81.20 and earlier, and CloudGuard Network Security R81.10 and earlier. Check Point advises upgrading to R81.20 Take 67 or later immediately. Organizations should also review firewall logs for anomalous IKE negotiation attempts and unexpected administrative sessions originating from external IPs.

Domain Intelligence

checkpoint.com — 87.0

checkpoint.com scores at 87.0, in the high-trust range. Check Point is the vendor that identified and patched both vulnerabilities on September 10, 2026, and has published full remediation guidance. The high score reflects checkpoint.com’s established infrastructure posture and should not be read as a finding about the severity of the vulnerabilities in its products, which at CVSS 9.8 are near-maximum.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 13, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026