Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Security Alert: Critical VPN Vulnerabilities in Check Point Products

Check Point has released security updates to address two critical VPN vulnerabilities (CVE-2026-85102 and CVE-2026-85103). Exploitation could allow unauthenticated remote attackers to execute malicious code and compromise affected systems.
 
Affected Systems:
  • Security Gateway and Check Point Spark Firewall: R81.20, R82, R82.10; R81.10.x, R82.00.x; End of Life (R80 – R81.10).
  • Security Management Server: R81.20, R82, R82.10; R81.10.x, R82.00.x; End of Life (R80 – R81.10).
 
Security Risks
 
The successful exploitation of these vulnerabilities could allow an unauthenticated remote attacker to gain unauthorized control of an affected Check Point system, potentially disrupting its security functions and compromising the security of the protected network.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
 
1. Apply the latest supported security updates for affected Checkpoint products as soon as possible to address the vulnerability.
 
2. Review Check Point advisories for guidance on affected products, mitigation steps, and remediation:
 

 

For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.
 
References

19 September 2026

© 2026 National Cyber Security Authority