CuraSec

Act active

Dutch NCSC Warns Critical Check Point VPN Flaws Face Imminent Exploit

  • Engineer — Act: Public PoCs exist on GitHub for both CVEs and a national NCSC is warning exploitation is imminent — patch Check Point VPN gateways to the vendor-fixed version immediately and verify no unauthorized access preceded the patch.
  • SOC/IR — Act: Edge VPN devices with public PoCs and an imminent-exploitation warning require an assume-breach posture — hunt for anomalous authentication events and lateral movement originating from Check Point VPN nodes since the CVEs were disclosed, and tune detections for post-exploitation activity on network edge appliances.
  • Leader — Act: Confirm whether Check Point VPN is present in your estate and verify emergency patching is already in motion; a government NCSC imminent-exploitation warning on a widely-deployed VPN with public PoC is likely to generate customer and board questions if exploitation materializes at scale.
  • Signals: CVE-2026-85102 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub · CVE-2026-85103 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.