Dutch Cyber Security Center Warns of Critical Check Point VPN Flaws
AI-generated from multiple sources. Verify before acting on this reporting.
THE HAGUE — The Dutch National Cyber Security Centre (NCSC) issued an urgent alert on Friday regarding the imminent exploitation of two critical vulnerabilities in Check Point VPN software, warning organizations that attackers could soon gain full control over affected systems. The advisory, released on Sept. 12, 2026, identifies the flaws as CVE-2026-85102 and CVE-2026-85103, describing them as high-risk threats capable of allowing remote attackers to execute arbitrary code without authentication.
The NCSC stated that successful exploitation of these defects could enable adversaries to view or modify confidential data, disrupt essential operations, and take complete control of network infrastructure. The vulnerabilities specifically target the secure remote access solutions widely deployed by enterprises and government agencies to protect sensitive communications. Because the flaws allow for remote code execution, attackers do not need physical access to the target network, significantly increasing the potential scope of an attack.
Check Point Software Technologies, a leading provider of cybersecurity products based in Israel, has been identified as the vendor affected by the security gaps. The NCSC emphasized that organizations relying on these specific versions of the VPN software must apply patches immediately or implement compensatory controls to mitigate the risk. The center noted that the window for exploitation is closing rapidly, with indicators suggesting that threat actors are actively scanning for unpatched systems.
The warning comes as global cybersecurity agencies have increasingly focused on securing remote access points following a surge in ransomware and data exfiltration campaigns targeting critical infrastructure. The NCSC's alert serves as a directive for Dutch entities to prioritize remediation, but the implications extend to any organization globally using the affected software versions. Security experts caution that the complexity of the vulnerabilities may require more than standard patching procedures, potentially necessitating temporary network segmentation or disabling specific remote access features until updates are verified.
While the NCSC has confirmed the existence and severity of the flaws, details regarding the specific methods attackers might use to exploit CVE-2026-85102 and CVE-2026-85103 remain under review. It is currently unclear whether any active breaches have already occurred or if the vulnerabilities are being leveraged in a coordinated campaign. The center has not yet released information on the number of organizations potentially impacted within the Netherlands or internationally.
As the situation develops, the NCSC continues to monitor threat actor activity and will provide further updates as new information becomes available. Organizations are urged to verify their software versions against the latest security advisories and maintain strict monitoring of network traffic for signs of unauthorized access. The urgency of the alert underscores the critical need for rapid response in an environment where remote work tools remain a primary target for cybercriminals.