Summary
The Dutch National Cyber Security Centre issued an imminent exploitation warning on September 12, 2026 for two critical vulnerabilities in Check Point Network Security gateways: CVE-2026-85102 and CVE-2026-85103. Both vulnerabilities carry a CVSS score of 9.8 and affect the IPSec VPN and SSL VPN components of Check Point’s Quantum Security Gateway and CloudGuard Network products. CVE-2026-85102 allows an unauthenticated remote attacker to execute arbitrary code on the gateway; CVE-2026-85103 allows memory disclosure that can be chained to improve exploitation reliability. Check Point released patches on September 10, 2026. The Dutch NCSC’s imminent warning reflects intelligence that exploitation is being actively prepared or has begun against unpatched internet-facing gateways.
Timeline
| Date | Event |
|---|---|
| Sep 10, 2026 | Check Point releases patches for CVE-2026-85102 and CVE-2026-85103 affecting Quantum Security Gateway and CloudGuard Network |
| Sep 11, 2026 | Proof-of-concept code for CVE-2026-85102 circulates in private channels |
| Sep 12, 2026 | Dutch NCSC issues imminent exploitation warning; advises immediate patching of all internet-facing Check Point gateways |
| Sep 13, 2026 | Active scanning for vulnerable Check Point gateways observed across multiple threat intelligence feeds |
What Happened
CVE-2026-85102 is a stack buffer overflow in Check Point’s IKE daemon, the component that handles IPSec VPN key negotiation. An unauthenticated attacker with network access to the gateway can send a malformed IKE packet that triggers the overflow and achieves remote code execution as root on the underlying operating system. No authentication, credentials, or prior access are required. CVE-2026-85103 is a separate memory disclosure vulnerability in the SSL VPN component that leaks heap contents, allowing an attacker to defeat ASLR and significantly increase the reliability of CVE-2026-85102 exploitation when chained.
Check Point Security Gateways are perimeter devices protecting corporate networks. Successful exploitation gives an attacker a root shell on the firewall itself — the network boundary device — with full visibility into traffic flowing through it, the ability to modify firewall rules, and a pivot point into the internal network behind it. The Dutch NCSC’s imminent warning indicates that exploitation has been observed or is credibly anticipated against Dutch government and critical infrastructure networks, consistent with a pattern of VPN gateway exploitation by state-sponsored actors throughout 2025 and 2026.
Affected products include Quantum Security Gateway R81.20 and earlier, and CloudGuard Network Security R81.10 and earlier. Check Point advises upgrading to R81.20 Take 67 or later immediately. Organizations should also review firewall logs for anomalous IKE negotiation attempts and unexpected administrative sessions originating from external IPs.
Domain Intelligence
checkpoint.com — 87.0
checkpoint.com scores at 87.0, in the high-trust range. Check Point is the vendor that identified and patched both vulnerabilities on September 10, 2026, and has published full remediation guidance. The high score reflects checkpoint.com’s established infrastructure posture and should not be read as a finding about the severity of the vulnerabilities in its products, which at CVSS 9.8 are near-maximum.
The Trust Observatory · thetrustobservatory.com · September 13, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026