Independent cybersecurity news and intelligence
HomeSourcesRSS
Cybersecurity News. Source-grounded Intelligence.
Back to newsroom
VulnerabilitiesCyberDeltaForce Newsroom

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.

BleepingComputerSep 12, 2026, 2:14 PM UTC3 min readCVE-2026-85102
IN 30 SECONDS

What you need to know

What happenedSource reporting

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.

Who is affectedSource reporting

Successful exploitation could let an attacker run code on a vulnerable system, which can lead to broader compromise depending on the privileges of the affected service.

Exploitation statusCDF assessment

No active exploitation was identified in the current reporting reviewed.

Why it mattersSource reporting

No exploitation flag is present in the retained CyberDeltaForce data at this time; that status can change as vendor and threat-intelligence reporting develops.

What to do nowCDF guidance

Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.

THE NEWS

What happened

Verified reporting in clear, practical language.

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The flaw is best understood as a code-execution weakness, rather than simply as a CVE number or severity score.

If the published conditions are met, the security consequence is attacker-controlled code execution. CVE-2026-85102 is the vulnerability identifier associated with this report. Successful exploitation could let an attacker run code on a vulnerable system, which can lead to broader compromise depending on the privileges of the affected service.

The reported consequence is code execution, meaning successful exploitation could make the affected application or process run attacker-controlled code. The operational question is not simply the severity score, but whether the affected component is deployed, reachable, business-critical and protected by compensating controls.

Real risk depends on exposure, exploitability, compensating controls and the importance of the affected asset—not the CVSS number alone. No exploitation flag is present in the retained CyberDeltaForce data at this time; that status can change as vendor and threat-intelligence reporting develops. Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.

Apply the vendor patch or mitigation for CVE-2026-85102 and validate the affected path after remediation. The current source set does not report active exploitation of CVE-2026-85102; that status should be monitored rather than treated as proof that exploitation is impossible.

The most useful validation after remediation is to confirm that the vulnerable path no longer permits the reported behavior and that the deployed release matches the vendor's corrected version. So far, researchers have not reported exploitation, but that can change as vendor, government or threat-intelligence reporting develops.

REFERENCES

Reference sources

CYBERDELTAFORCE INTELLIGENCE

Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.

DEFENDER ACTIONS

What security teams should do now

  • Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.
  • Apply the vendor patch or mitigation for CVE-2026-85102 and validate the affected path after remediation.
OPEN QUESTIONS

What is not yet confirmed

  • So far, researchers have not reported exploitation, but that can change as vendor, government or threat-intelligence reporting develops.
Continue the story

Related Cybersecurity Coverage

More cybersecurity news
CyberDeltaForce publication standards