Dutch NCSC warns that two critical Check Point VPN flaws (CVE-2026-85102 and CVE-2026-85103) could be exploited imminently. Here's what you need to do now.
The Dutch Nationaal Cyber Security Centrum (NCSC) just dropped a warning that should make anyone running Check Point VPN sit up straight. Two critical vulnerabilities—CVE-2026-85102 and CVE-2026-85103—are sitting there, waiting to be exploited. And according to the NCSC, that exploitation isn't a matter of if, but when.
If you're managing remote access for a company, this is your cue to stop scrolling and start patching.
### Why These Two Flaws Are Different
Most vulnerabilities get disclosed, patched, and forgotten. These two feel different. The NCSC rarely issues imminent exploitation warnings unless they've seen something concrete—proof-of-concept code circulating, chatter on underground forums, or both. That means the window between disclosure and attack is shrinking fast.
So what's actually at risk? Check Point VPNs are the front door for thousands of businesses. If an attacker walks through that door, they're not just inside your network—they're inside with the keys to everything.
### The Real-World Impact
Imagine a remote employee logging in from a coffee shop. They think they're safe because the VPN is on. But if that VPN has an unpatched flaw, the attacker doesn't need to trick the employee. They just slip in through the same tunnel and start moving laterally.
- **Data theft:** Customer records, intellectual property, financial data—all fair game.
- **Ransomware deployment:** Once inside, attackers can encrypt everything and demand payment.
- **Persistent access:** They can create backdoors that survive even after you patch.
And here's the kicker: many organizations don't even know they're running a vulnerable version. Check Point has released patches, but if you haven't applied them yet, you're a sitting duck.
### What You Should Do Right Now
1. **Check your version.** Log into your Check Point management console and verify whether you're affected by CVE-2026-85102 or CVE-2026-85103.
2. **Patch immediately.** Don't wait for the next maintenance window. This is an emergency.
3. **Enable multi-factor authentication.** It won't fix the flaw, but it adds a layer that stops most automated attacks.
4. **Monitor for unusual activity.** Look for logins from strange locations or at odd hours.
> "The time to act is before the first exploit lands, not after your data is gone." — Robert Moore, Lead Antidetect Browser Specialist & Digital Privacy Strategist
### The Bigger Picture
This isn't just about Check Point. It's a reminder that the tools we trust to keep us safe can become our biggest liability if we ignore updates. VPNs are essential, but they're not magic. They need care, attention, and yes, occasional panic-driven patching.
If you're not sure where to start, talk to your IT team today. Or if you're the IT team, grab a coffee and get to work. The attackers aren't waiting.