CVE-2026-85102
Improper Certificate Validation in Quantum Security Gateway
Severity
Critical 9.8
CVSS 3.1
Exploited
Yes — in CISA KEV
Added Sep 22, 2026
EPSS
0.007
50.2th percentile
Discovered by
Not disclosed
Published
Sep 9, 2026
Assigned by checkpoint
Description
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
Weakness: CWE-295
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Check Point | Quantum Security Gateway | Firewall / NGFW | cna-assigner |
Vendor-reported products (1)
- checkpoint · Quantum Security Gateway
References
- https://support.checkpoint.com/results/sk/sk1000117
- https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85102