Notice
Dutch NCSC warns Check Point VPN flaws face imminent exploitation
The Dutch Nationaal Cyber Security Centrum says two critical Check Point VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, face imminent exploitation.
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN. The vulnerabilities are tracked as CVE-2026-85102 and CVE-2026-85103.
The warning names no specific mitigation steps. Teams running Check Point VPN should watch for vendor guidance and apply fixes as soon as Check Point publishes them.
Our reading
Our reading is that Check Point VPN operators should treat this as a high-priority advisory and follow vendor guidance closely, since the warning itself names no mitigation steps.
What to do or watch
Check Point VPN operators should watch for vendor guidance and apply fixes as soon as Check Point publishes them, since the Dutch NCSC warning names no specific mitigation steps. The unresolved question is when Check Point will publish fixes or mitigation guidance.
Source details and supporting facts
Each line is stated by the page named above it.
Stated by BleepingComputer
- The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN.
- The flaws are tracked as CVE-2026-85102 and CVE-2026-85103.
Sources
- BleepingComputerText stored 14 September 2026
How this story was checked. Written from the 1 page listed above, stored 14 September 2026; claims checked against that stored text on 14 September 2026.
What that means
- 2 of 2 reported statements were confirmed against the page that carries them; the rest were removed rather than published.
- Figures in the text were required to appear in the stored source text: yes. Identifiers: yes.
- The check reads stored text only: no claim rests on a fresh look that did not happen.
- Where the reporting was silent, the text says so instead of filling the gap.
More from Security
Report
Spain's AEPD logs its first report of an AI-agent data breach — unverified, but with a concrete credential warning
Brief
Google releases September 2026 patches for Pixel, fixing actively exploited zero-day
Brief