๐Ÿ”ด CVE-2026-85102

CVE-2026-85102 is a critical (CVSS 9.8) improper certificate validation vulnerability in Check Point Quantum Security Gateway affecting VPN negotiation. An unauthenticated remote attacker can exploit this flaw over the network without any user interaction to achieve arbitrary code execution directly on the gateway appliance. As a perimeter security device with VPN services that must be internet-exposed to function, virtually all affected deployments are directly reachable from the internet.

โ† Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 โ€” Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

๐Ÿ“‹ Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-09-09

Added to CISA KEV: 2026-09-22 13 DAYS BETWEEN CVE AND KEV

๐ŸŽฏ Recommendations:

๐Ÿ” Web Intelligence (Kagi ยท 2026-09-22)

Summary

CVE-2026-85102 is a critical security vulnerability (CVSS 9.8) affecting Check Point Quantum Security Gateways, specifically involving improper certificate trust validation during VPN negotiation. This flaw allows an unauthenticated remote attacker to bypass authentication mechanisms and execute arbitrary code on the affected Security Gateway. Given the nature of the device as a perimeter security component, this vulnerability is highly severe, as it provides attackers with a direct path to compromise network infrastructure and gain unauthorized access to internal resources.

Exploitation

  • Active Exploitation: While Check Point reported no initial evidence of exploitation at the time of disclosure, regional warnings from organizations like the Dutch NCSC have noted that exploitation is considered imminent.
  • Threat Actors/Campaigns: There are no specific threat actors or ransomware campaigns publicly attributed to this vulnerability at this time.
  • Proof-of-Concept/Tools: Proof-of-concept exploit code or automated attack tools have not been publicly detailed, though security research groups have characterized the flaw as a "one-day" exploitation risk due to the publicly available patch details.
  • Attack Prerequisites: The attack can be launched remotely over the network without requiring prior authentication or user interaction.

Affected Products & Patches

  • Affected Products: Check Point Quantum Security Gateways utilizing Remote Access and Site-to-Site VPN functionality.
  • Patch Availability: Security patches and hotfixes were officially released by Check Point on September 9, 2026.
  • Mitigations/Workarounds: Organizations are strongly advised to apply the provided patches immediately. Check Point has issued specific security advisories (e.g., sk1000117) providing guidance on remediation and log hunting queries to detect potential signs of compromise.

Impact

  • Access and Capabilities: Successful exploitation enables unauthenticated remote code execution, granting the attacker full control over the Security Gateway. This allows for total circumvention of security policies, interception of VPN traffic, and potential lateral movement into the internal network.
  • Business Risk: For internet-facing deployments, the risk is extreme, as these devices are typically the primary point of entry between the public internet and private corporate environments. Compromise of the Security Gateway effectively negates the security posture of the entire protected network, risking data breaches, persistent unauthorized access, and complete system takeover.