What it is
CVE-2026-85102 is an unauthenticated Improper Certificate Validation in Quantum Security Gateway. Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an...
Vulnerability report
Improper Certificate Validation in Quantum Security Gateway
Check Point / Quantum Security Gateway · R82.10 with Jumbo Hotfix Take 43 or below
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-85102 is an unauthenticated Improper Certificate Validation in Quantum Security Gateway. Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an...
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
Check Point / Quantum Security Gateway r82.10 with jumbo hotfix take 43 or below.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Check Point Blog
A trusted third party reported exploitation.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Check Point Blog First | 2026-09-22 13:49 UTC |
| CISA | 2026-09-22 19:50 UTC |
| CVE | 2026-09-22 20:01 UTC |
| Security Affairs | 2026-09-23 21:21 UTC |
| Qualys ThreatPROTECT | 2026-09-24 05:20 UTC |
| SOCRadar | 2026-09-25 08:20 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
7.5%
Recent mention · Arctic Wolf
AI is changing how security operations work. It can process more data, reduce repetitive work, and move investigations forward faster than human teams could on their own. But speed and scale are not the only factors security leaders should be considering. The more important...
Read full advisoryRecent mention · Arctic Wolf
How the Aurora Agentic SOC Is Building the Next Generation of SOC AnalystsArctic Wolf · 25 Sep 2026
AI is changing how security operations work. It can process more data, reduce repetitive work, and move investigations forward faster than human teams could on their own. But speed and scale are not the only factors security leaders should be considering. The more important question is what happens to human expertise when machines take on ... How the Aurora Agentic SOC Is Building the Next Generation of SOC Analysts
Recent mention · SOCRadar
Check Point Pre-Auth Flaws Under AttackSOCRadar · 24 Sep 2026
Check Point Pre-Auth Flaws Under Attack Check Point has warned that two critical, pre-authentication vulnerabilities affecting its security products are being actively exploited. CVE-2026-85102 affects VPN certificate ha
Recent mention · Qualys ThreatPROTECT
CISA Warns of Check Point Vulnerabilities Exploited in Attacks (CVE-2026-85102 & CVE-2026-93616)Qualys ThreatPROTECT · 24 Sep 2026
Check Point has two vulnerabilities that are being exploited in the wild, tracked as CVE-2026-85102 & CVE-2026-93616. The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerabilities to its Known Exploited Vulnerabilities Catalog, urging users to patch before September 25, 2026. CVE-2026-85102: Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN The vulnerability has a … Continue reading "CISA Warns of Check Point Vulnerabilities Exploited in Attacks (CVE-2026-85102 & CVE-2026-93616)"
Recent mention · Security Affairs
U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs · 23 Sep 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks […]
Recent mention · Check Point Blog
Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616Check Point Blog · 22 Sep 2026
As part of Check Point’s Frontier AI Readiness Program, we continue to release Jumbo hotfixes with security fixes and hardening improvements for our Firewall and Management products. This advisory addresses the active exploitation described below, and the immediate steps customers should take to protect affected systems. Check Point Research has identified active exploitation of two vulnerabilities affecting Security Gateway and Security Management: A fix for CVE-2026-85102 has been available since September 9, and customers who have applied it are already protected. CVE-2026-93616 is a...
Recent mention · The Hacker News
Check Point Warns of Management Server Zero-Day Exploited in Targeted AttacksThe Hacker News · 22 Sep 2026
Swati KhandelwalSep 22, 2026Network Security / Vulnerability Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point gateways it manages. Separately, Check Point said attackers have been trying since September 12 to exploit a VPN flaw it fixed on September 9....
Recent mention · BleepingComputer
New Check Point flaw lets hackers execute code with root privilegesBleepingComputer · 18 Sep 2026
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. [...]
Recent mention · Arctic Wolf
Check Point VPN Critical RCE Vulnerabilities CVE-2026-85102 & CVE-2026-85103Arctic Wolf · 14 Sep 2026
Threat Summary Patches have now been released addressing two critical vulnerabilities: CVE-2026-85102, which affects Security Gateway and Spark Firewall, and CVE-2026-85103, which affects Security Gateway, Management Server, and Spark Firewall. CVE-2026-85102 is an improper certificate validation during VPN negotiation and CVE-2026-85103 heap overflow in ASN.1 certificate decoding. Both bugs open the door to unauthenticated remote ... Check Point VPN Critical RCE Vulnerabilities CVE-2026-85102 & CVE-2026-85103
Recent mention · BleepingComputer
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentBleepingComputer · 12 Sep 2026
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]
Recent mention · NCSC Security Advisories
NCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN productenNCSC Security Advisories · 10 Sep 2026
Check Point heeft 2 kritieke kwetsbaarheden verholpen. De kwetsbaarheid met kenmerk CVE-2026-85102 heeft een CVSS-score van 9,8. De kwetsbaarheid bevindt zich in het VPN-onderhandelingsproces van de Quantum Security Gateway en wordt veroorzaakt door onjuiste validatie van certificaatvertrouwen. Hierdoor kan een niet-geauthenticeerde externe aanvaller authenticatiecontroles omzeilen en willekeurige code uitvoeren op de Security Gateway. Exploitatie vindt plaats tijdens de VPN-onderhandeling, waarbij certificaatgegevens onvoldoende worden gevalideerd. De kwetsbaarheid geldt voor Security...
Recent mention · CERT Polska
Krytyczne podatności w produktach firmy Check PointCERT Polska · 10 Sep 2026
Zespół CERT Polska informuje o krytycznych podatnościach w produktach firmy Check Point.Podatności, oznaczone jako CVE-2026-85102 oraz CVE-2026-85103, umożliwiają atakującemu zdalne wykonanie dowolnego kodu na urządzeniu. Dotyczą one produktów: Security Gateway, Security Management Server oraz Check Point Spark Firewall.Rekomendujemy niezwłoczną instalację aktualizacji:LivePatch dla wersji R81.20, R82 oraz R82.10 - jeśli włączona jest jego automatyczna instalacja, łatka powinna wgrać się automatycznie,Jumbo Hotfix Accumulator: R82.10 (od Take 44), R82 (od Take 126) oraz R81.20 (od Take...
Timeline
08:20 UTC
Exploitation attested by an external source
05:20 UTC
Exploitation attested by an external source
21:21 UTC
Exploitation attested by an external source
20:01 UTC
Exploitation attested by an external source
19:50 UTC
Listed in the CISA Known Exploited Vulnerabilities catalog
13:49 UTC
High-confidence, third-party attested exploitation
08:20 UTC
Pro and Enterprise Watch users had 1 week of early warning before CISA KEV. Also 1 week before Previdian confirmed it as a KEV.
13:00 UTC
Vulnerability disclosed publicly
06:38 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-85102
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-85102",
"confidence": "Confirmed",
"cvss_score": 9.8,
"cvss_estimated": false,
"epss_score": 0.07546,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}