Check Point VPN Certificate Vulnerability: Patch Now

A Check Point VPN certificate vulnerability pair (CVSS 9.8) allows pre-auth RCE. Dutch NCSC warns exploitation is imminent; patch today.

Check Point disclosed a Check Point VPN certificate vulnerability pair, CVE-2026-85102 and CVE-2026-85103, both CVSS 9.8, on September 9, and the Dutch National Cyber Security Centre has since warned that large-scale exploitation is likely imminent, even though Check Point itself has not yet observed attacks in the wild. Both flaws allow unauthenticated remote code execution…

Read More