Introduction
On September 9, 2026, Check Point released emergency patches for two critical vulnerabilities affecting its VPN gateways. Four days later, on September 13, the Dutch National Cyber Security Centre (NCSC) issued a public warning: large-scale exploitation was imminent, and a significant share of deployed appliances remained unpatched.
That four-day window — between patch availability and a national regulator sounding the alarm — is not a minor footnote. It directly challenges the patch management maturity of any organisation running critical network equipment.
Two Flaws, One Near-Perfect Score
Both vulnerabilities, referenced as CVE-2026-85102 and CVE-2026-85103, carry a CVSS score of 9.8/10. The first stems from faulty certificate data validation during VPN negotiation, allowing an unauthenticated attacker to execute arbitrary code on a Quantum Security Gateway. The second is a buffer overflow in the ASN.1 certificate decoder, exploitable across Security Gateways, Security Management Servers, and Quantum Spark appliances.
Affected versions span the R81.20, R82, and R82.10 branches below their patched thresholds (Take 166, Take 126, and Take 44 respectively), along with several end-of-life older releases. As of now, no confirmed exploitation in the wild has been reported — but the NCSC is unambiguous: it is only a matter of time.
The Real Question for Your CIO
The technical response is straightforward: apply the available patches and restrict UDP 500 and 4500 access to trusted IP addresses until the update is in place. Check Point also offers a LivePatch option for environments that cannot afford a service interruption.
But behind the patch lies an organisational question that too few IT leadership teams have formally answered: can your team deploy an emergency patch to a critical network component in under 48 hours, without triggering an unplanned service outage?
For remote-access VPNs, the honest answer is rarely yes by default. These appliances tend to be treated as stable infrastructure — infrequently updated, sitting outside the normal patch management cycle. That blind spot is exactly what makes them prime targets: they are internet-facing, often under-monitored, and maintaining them requires coordinated effort across network, security, and business teams — coordination that is seldom well-rehearsed.
NIS2 and the Obligation to Act Fast
NIS2, transposed into national law across EU member states since early 2025, requires essential and important entities to actively manage vulnerabilities as part of their cybersecurity measures. That includes addressing critical patches within timeframes proportionate to the risk level — and for a CVSS 9.8 with imminent exploitation announced, that window is not measured in weeks.
VPN appliances appear consistently within the NIS2 perimeter of industrial organisations, digital service providers, and critical infrastructure operators. A delayed deployment is no longer just a technical risk: it is a documentable compliance gap, one that could feature prominently in any post-incident regulatory review.
What This Means in Practice
The Check Point incident is an opportunity to stress-test your process before an attacker does it for you. Immediate action points: verify the exact inventory of deployed versions, confirm that your LivePatch or Jumbo Hotfix deployment procedure is documented and executable under pressure, and ensure that VPN access restrictions to trusted IPs are already in place as an interim measure.
The vulnerability window open today will not stay open indefinitely. The question is whether your processes will be ready to close it before someone else walks through it.

