Act
active
Dutch NCSC Warns Critical Check Point VPN Flaws Face Imminent Exploit
- Engineer — Act: Public PoCs exist on GitHub for both CVEs and a national NCSC is warning exploitation is imminent — patch Check Point VPN gateways to the vendor-fixed version immediately and verify no unauthorized access preceded the patch.
- SOC/IR — Act: Edge VPN devices with public PoCs and an imminent-exploitation warning require an assume-breach posture — hunt for anomalous authentication events and lateral movement originating from Check Point VPN nodes since the CVEs were disclosed, and tune detections for post-exploitation activity on network edge appliances.
- Leader — Act: Confirm whether Check Point VPN is present in your estate and verify emergency patching is already in motion; a government NCSC imminent-exploitation warning on a widely-deployed VPN with public PoC is likely to generate customer and board questions if exploitation materializes at scale.
- Signals: CVE-2026-85102 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub · CVE-2026-85103 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.