CVE-2026-85102
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
- Published Sep 9, 2026
- CVSS 9.8 critical
- 7.5% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A fix is available
Affected software
In the news
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes The Hacker News ·
- ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats The Hacker News ·
- Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks The Hacker News ·
- CISA Adds Four Known Exploited Vulnerabilities to Catalog CISA ·
- Critical Vulnerabilities in Check Point Products CERT-EU ·
- Check Point security advisory (AV26-902) – Update 2 Canadian Centre for Cyber Security ·