CVE-2026-85102 is a critical (CVSS 9.8) improper certificate validation vulnerability in Check Point Quantum Security Gateway affecting VPN negotiation. An unauthenticated remote attacker can exploit this flaw over the network without any user interaction to achieve arbitrary code execution directly on the gateway appliance. As a perimeter security device with VPN services that must be internet-exposed to function, virtually all affected deployments are directly reachable from the internet.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-09-09
Added to CISA KEV: 2026-09-22 13 DAYS BETWEEN CVE AND KEV
CVE-2026-85102 is a critical security vulnerability (CVSS 9.8) affecting Check Point Quantum Security Gateways, specifically involving improper certificate trust validation during VPN negotiation. This flaw allows an unauthenticated remote attacker to bypass authentication mechanisms and execute arbitrary code on the affected Security Gateway. Given the nature of the device as a perimeter security component, this vulnerability is highly severe, as it provides attackers with a direct path to compromise network infrastructure and gain unauthorized access to internal resources.