Skip to content

CVE-2026-85102

Check Point Quantum Security Gateway improper certificate validation allows unauthenticated code execution (CVE-2026-85102)

Critical 9.8 KEV Vendor: Check Point Published · Updated

Check Point Quantum Security Gateway has a critical certificate validation flaw (CVE-2026-85102) that lets unauthenticated attackers run code over the network. CISA KEV lists it as actively exploited. Apply Check Point's SK1000117 mitigation immediately.

What happened

During VPN negotiation, Check Point Quantum Security Gateway does not properly validate certificates, which allows an unauthenticated remote attacker to execute arbitrary code on the gateway. The CVSS 3.1 score is 9.8 (critical): the vulnerability is reachable over the network, has low attack complexity, requires no privileges or user interaction, and has high impact on confidentiality, integrity and availability.

CISA added CVE-2026-85102 to the Known Exploited Vulnerabilities catalog on 2026-09-22 and records exploitation as active. CISA's SSVC assessment also marks exploitation as active. The record lists no public disclosure, and no separate Check Point statement on exploitation is included in the information supplied here.

Who is affected

The affected product is Check Point Quantum Security Gateway. The vulnerable versions are:

  • R82.10 with Jumbo Hotfix Take 43 or below
  • R82 with Jumbo Hotfix Take 125 or below
  • R81.20 with Jumbo Hotfix Take 165 or below

The vulnerable function is reached during VPN negotiation, so organisations using these gateways to terminate remote-access or site-to-site VPNs should verify their installed version and Jumbo Hotfix Take.

What to do now

  1. Consult Check Point's SK1000117 advisory and apply the vendor's fix or mitigation. The record says a fix is available, but no specific fixed build is listed in the data shown here; confirm the exact target version with Check Point before rolling out.
  2. Apply CISA's required action for the KEV entry: apply mitigations in accordance with vendor instructions and follow any applicable BOD 26-04 guidance. The KEV due date was 2026-09-25.
  3. If you cannot apply the fix immediately, reduce exposure to the VPN negotiation service. Restrict access to trusted source networks and disable VPN features that are not required.
  4. Confirm affected gateways are not reachable from untrusted networks until they are confirmed fixed.

Beyond the patch

Because CISA records active exploitation of a pre-authentication flaw on a VPN gateway, this is not only a patch management issue; you need to know whether an affected gateway has already been reached. Managed Detection & Response (MDR) is built for detection and response work around exploited perimeter systems. To reduce exposure before the next advisory, Virtual CISO Services (vCISO) can help you map and review which VPN services should be reachable and from where.

Affected and fixed versions

ProductAffectedFixed in
Quantum Security GatewayR82.10 with Jumbo Hotfix Take 43 or below
R82 with Jumbo Hotfix Take 125 or below
R81.20 with Jumbo Hotfix Take 165 or below
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.