CVE-2026-85102
Check Point Quantum Security Gateway improper certificate validation allows unauthenticated code execution (CVE-2026-85102)
Check Point Quantum Security Gateway has a critical certificate validation flaw (CVE-2026-85102) that lets unauthenticated attackers run code over the network. CISA KEV lists it as actively exploited. Apply Check Point's SK1000117 mitigation immediately.
What happened
During VPN negotiation, Check Point Quantum Security Gateway does not properly validate certificates, which allows an unauthenticated remote attacker to execute arbitrary code on the gateway. The CVSS 3.1 score is 9.8 (critical): the vulnerability is reachable over the network, has low attack complexity, requires no privileges or user interaction, and has high impact on confidentiality, integrity and availability.
CISA added CVE-2026-85102 to the Known Exploited Vulnerabilities catalog on 2026-09-22 and records exploitation as active. CISA's SSVC assessment also marks exploitation as active. The record lists no public disclosure, and no separate Check Point statement on exploitation is included in the information supplied here.
Who is affected
The affected product is Check Point Quantum Security Gateway. The vulnerable versions are:
- R82.10 with Jumbo Hotfix Take 43 or below
- R82 with Jumbo Hotfix Take 125 or below
- R81.20 with Jumbo Hotfix Take 165 or below
The vulnerable function is reached during VPN negotiation, so organisations using these gateways to terminate remote-access or site-to-site VPNs should verify their installed version and Jumbo Hotfix Take.
What to do now
- Consult Check Point's SK1000117 advisory and apply the vendor's fix or mitigation. The record says a fix is available, but no specific fixed build is listed in the data shown here; confirm the exact target version with Check Point before rolling out.
- Apply CISA's required action for the KEV entry: apply mitigations in accordance with vendor instructions and follow any applicable BOD 26-04 guidance. The KEV due date was 2026-09-25.
- If you cannot apply the fix immediately, reduce exposure to the VPN negotiation service. Restrict access to trusted source networks and disable VPN features that are not required.
- Confirm affected gateways are not reachable from untrusted networks until they are confirmed fixed.
Beyond the patch
Because CISA records active exploitation of a pre-authentication flaw on a VPN gateway, this is not only a patch management issue; you need to know whether an affected gateway has already been reached. Managed Detection & Response (MDR) is built for detection and response work around exploited perimeter systems. To reduce exposure before the next advisory, Virtual CISO Services (vCISO) can help you map and review which VPN services should be reachable and from where.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Quantum Security Gateway | R82.10 with Jumbo Hotfix Take 43 or below R82 with Jumbo Hotfix Take 125 or below R81.20 with Jumbo Hotfix Take 165 or below | No fixed version listed yet |