Critical Security Flaws Leave Corporate Network Gateways Vulnerable to Immediate Hijacking
The Hague, Sunday, 13 September 2026.
The Dutch National Cyber Security Centre warns that hackers are poised to exploit two critical flaws in Check Point software, allowing them to seize complete control of corporate networks.
Anatomy of a High-Severity Threat
The alarm sounded by the Dutch National Cyber Security Centre (NCSC) highlights two critical security vulnerabilities, designated as CVE-2026-85102 and CVE-2026-85103, which carry a near-perfect Common Vulnerability Scoring System (CVSS) rating of 9.8 out of 10 [2][6][8]. These flaws reside within the Virtual Private Network (VPN) software components of Check Point Software, a major provider of enterprise security solutions [2][4][7]. Security analysts warn that because corporate VPN gateways serve as the primary entry points for remote workforces, they are highly attractive targets for malicious actors seeking to compromise entire corporate networks [2]. As of September 13, 2026, while no public exploits have been reported in the wild, the NCSC assesses that the likelihood of imminent exploitation is high [2].
How the Vulnerabilities Work
The first vulnerability, CVE-2026-85102, stems from improper certificate trust validation during the VPN negotiation flow [6][7][8]. When a remote client attempts to establish a connection, the security gateway fails to properly validate the incoming certificate data [2][6]. An unauthenticated remote attacker can exploit this weakness to bypass standard authentication barriers and execute arbitrary code directly on the Security Gateway [2][6][8]. This vulnerability impacts systems configured for either Site-to-Site VPN or Remote Access VPN connections [8].
Scope of Affected Enterprise Systems
The vulnerabilities impact a broad range of Check Point deployments, including Quantum Security Gateway, Security Management Server, and Spark Firewall models [6][8]. Specifically, the affected software versions encompass active release branches R81.20, R82, and R82.10, alongside smaller branch deployments like R81.10.x and R82.00.x [2][8]. Furthermore, several legacy, end-of-support versions remain highly vulnerable, including R80 through R80.40, R81, and R81.10 [2][6][8]. Check Point has confirmed that its newer R82.20 release is unaffected by these security flaws [2][6].
Immediate Remediation and Defensive Actions
Check Point released emergency security updates on September 9, 2026, accompanied by security advisories sk1000117 and sk1000118 [2][6]. This means organizations have had a brief window of 4 days to secure their perimeters before the threat of active exploitation escalates [2][6]. For administrators running R81.20, R82, or R82.10, Check Point offers automatic protection via its LivePatch (CPLP) service, which applies the necessary hotfixes without requiring a server reboot [2][4]. Other configurations must manually install designated Jumbo Hotfix Accumulator packages, such as Take 166 for R81.20, Take 126 for R82, or Take 44 for R82.10 [2].
Bronnen
- blog.netmanageit.com
- atlabyte.com
- support.checkpoint.com
- community.checkpoint.com
- support.checkpoint.com
- securityonline.info
- x.com
- cert.europa.eu