Check PointCVE-2026-85102
Check Point Quantum Security Gateway: remote code execution
Critical9.8CVE-2026-85102 · Published Sep 9, 2026 · updated Sep 23, 2026
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Quantum Security Gateway Product | <= R82.10 with Jumbo Hotfix Take 43 or below | No fix yet |
| <= R82 with Jumbo Hotfix Take 125 or below | No fix yet | |
| <= R81.20 with Jumbo Hotfix Take 165 or below | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-295
- www.cve.org/CVERecord?id=CVE-2026-85102
- nvd.nist.gov/vuln/detail/CVE-2026-85102
- support.checkpoint.com/results/sk/sk1000117
- blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85102
More Check Point advisories
All Check Point| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 22 | Check Point Quantum Security Management: path traversal | Critical9.8 | No fix yet |
| Sep 16 | Check Point Quantum Security Management: stack buffer overflow | Critical9.8 | No fix yet |
| Sep 9 | Check Point Quantum Security: heap buffer overflow | Critical9.8 | No fix yet |
| Aug 3 | Check Point Multi-Domain Security Management Server: authentication bypass | Critical9.3 | No fix yet |
| Jul 22 | Check Point Security Management: authentication bypass | Critical9.1 | No fix yet |
| Jul 22 | Check Point Gaia Portal: code execution | High7.5 | No fix yet |