Summary
- Two Check Point VPN vulnerabilities have received CVSS scores of 9.8 from the Dutch NCSC.
- The flaws could allow unauthenticated remote code execution on affected systems.
- No mass exploitation had been confirmed when the warning was issued, although the NCSC expects attempts to follow.
The Netherlands’ national cyber security authority has warned that two critical vulnerabilities in Check Point VPN products could become targets for large-scale exploitation, putting another class of internet-facing security appliance under immediate scrutiny.
The Dutch National Cyber Security Centre (NCSC) assigned CVSS scores of 9.8 to CVE-2026-85102 and CVE-2026-85103, both of which affect Check Point VPN technology. The agency said the vulnerabilities could allow an unauthenticated attacker to execute code remotely on affected systems.
At the time of its 10 September warning, the NCSC said it was not aware of public exploit code and had not confirmed active exploitation. Check Point likewise said it had no indication of active exploitation. The Dutch agency nevertheless said it expected attempts to exploit the flaws at scale and urged affected organisations to update systems promptly.
Check Point has made fixes available, including through its LivePatch mechanism for supported deployments. The distinction between a critical vulnerability and a confirmed exploitation campaign remains important: the Dutch warning is based on the severity, accessibility, and likely attractiveness of the affected products rather than evidence that widespread compromise has already occurred.
VPN gateways occupy an unusually sensitive position in enterprise architecture because they are deliberately exposed to external connections while also providing authenticated routes into internal environments. A vulnerability that removes the authentication barrier can therefore collapse two of the assumptions on which remote-access security depends: that the gateway itself is trustworthy and that an attacker must first obtain valid credentials.
Security appliances have repeatedly become high-value targets for precisely that reason. Edge devices are often reachable from the public internet, may not generate the same telemetry as endpoint systems, and can remain in service for long periods because maintenance risks interrupting remote access or other business-critical connectivity. Those operational constraints can turn a patching delay into a meaningful exposure window.
The warning also illustrates the limits of treating perimeter security products as passive controls. Firewalls, VPN concentrators, secure access gateways, and similar equipment are software systems with their own vulnerability lifecycles. When flaws emerge in those systems, the control intended to mediate access can become the route around it.
European organisations have additional reasons to treat externally exposed infrastructure as an operational resilience issue rather than simply a vulnerability-management task. NIS2 and related national requirements place growing emphasis on risk management, incident handling, supply chain security, and the resilience of network and information systems. A critical flaw in remote-access infrastructure can cut across several of those areas at once.
The immediate position is narrower than some early vulnerability warnings can imply. There is no confirmed basis to say that CVE-2026-85102 or CVE-2026-85103 is being exploited at scale. The Dutch NCSC’s assessment is that exploitation is likely to follow, while fixes are already available.
That leaves the exposure dependent largely on which organisations are running affected products, whether those systems are externally reachable, and how quickly maintenance releases or LivePatch protections reach production environments. If exploitation does begin, internet-facing gateways are likely to provide attackers with a relatively easy population of targets to identify.





