Vulnerability report

Exploited in the wild Confirmed confidence In CISA KEV

CVE-2026-85102

Improper Certificate Validation in Quantum Security Gateway

Check Point / Quantum Security Gateway · R82.10 with Jumbo Hotfix Take 43 or below

Severity
CVSS 9.8 · Critical
Confidence
Confirmed
Exploit status
Exploited in the wild
EPSS
7.5%
First observed
—
Last observed
—

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2026-85102 is an unauthenticated Improper Certificate Validation in Quantum Security Gateway. Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an...

Is it exploited?

Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.

Who is affected?

Check Point / Quantum Security Gateway r82.10 with jumbo hotfix take 43 or below.

What should we do?

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Overview

Improper Certificate Validation in Quantum Security Gateway

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

checkpoint Affected
Quantum Security Gateway
R82.10 with Jumbo Hotfix Take 43 or below R82 with Jumbo Hotfix Take 125 or below R81.20 with Jumbo Hotfix Take 165 or below
Published
09 Sep 2026
Exploitation Reported
22 Sep 2026
Attack vector
Remote
Complexity
Low
Privileges
None
User interaction
None

Tags

cisa

CVE References

Exploitation evidence

Why Previdian marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

Check Point Blog

Recorded 22 Sep 2026

A trusted third party reported exploitation.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the Previdian Pro API.

Learn about Pro API access
Source Added
Check Point Blog First 2026-09-22 13:49 UTC
CISA 2026-09-22 19:50 UTC
CVE 2026-09-22 20:01 UTC
Security Affairs 2026-09-23 21:21 UTC
Qualys ThreatPROTECT 2026-09-24 05:20 UTC
SOCRadar 2026-09-25 08:20 UTC

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
User-Agents
Callback hosts
0
0
0

Request targets and User-Agents available in Pro. Callback host details available in Enterprise.

Scanner coverage

No scanner integrations recorded yet.

Virtual patch status

No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.

Learn about virtual patches →

No detection artifacts or sensor request patterns are available for this CVE yet.

Check back as sensor telemetry and scanner integrations are updated.

Risk and context

Severity, weaknesses, and research context

CVSS v3.1

9.8 Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

7.5%

Recent mention · Arctic Wolf

How the Aurora Agentic SOC Is Building the Next Generation of SOC Analysts

AI is changing how security operations work. It can process more data, reduce repetitive work, and move investigations forward faster than human teams could on their own. But speed and scale are not the only factors security leaders should be considering. The more important...

Read full advisory

All Mentions

Recent mention · Arctic Wolf

How the Aurora Agentic SOC Is Building the Next Generation of SOC Analysts

Arctic Wolf · 25 Sep 2026

AI is changing how security operations work. It can process more data, reduce repetitive work, and move investigations forward faster than human teams could on their own. But speed and scale are not the only factors security leaders should be considering. The more important question is what happens to human expertise when machines take on ... How the Aurora Agentic SOC Is Building the Next Generation of SOC Analysts

Recent mention · SOCRadar

Check Point Pre-Auth Flaws Under Attack

SOCRadar · 24 Sep 2026

Check Point Pre-Auth Flaws Under Attack Check Point has warned that two critical, pre-authentication vulnerabilities affecting its security products are being actively exploited. CVE-2026-85102 affects VPN certificate ha

Recent mention · Qualys ThreatPROTECT

CISA Warns of Check Point Vulnerabilities Exploited in Attacks (CVE-2026-85102 & CVE-2026-93616)

Qualys ThreatPROTECT · 24 Sep 2026

Check Point has two vulnerabilities that are being exploited in the wild, tracked as CVE-2026-85102 & CVE-2026-93616. The Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerabilities to its Known Exploited Vulnerabilities Catalog, urging users to patch before September 25, 2026. CVE-2026-85102: Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN The vulnerability has a … Continue reading "CISA Warns of Check Point Vulnerabilities Exploited in Attacks (CVE-2026-85102 & CVE-2026-93616)"

Recent mention · Security Affairs

U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · 23 Sep 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-85102 resides in the VPN negotiation process and lets an unauthenticated attacker bypass security checks […]

Recent mention · Check Point Blog

Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616

Check Point Blog · 22 Sep 2026

As part of Check Point’s Frontier AI Readiness Program, we continue to release Jumbo hotfixes with security fixes and hardening improvements for our Firewall and Management products. This advisory addresses the active exploitation described below, and the immediate steps customers should take to protect affected systems. Check Point Research has identified active exploitation of two vulnerabilities affecting Security Gateway and Security Management: A fix for CVE-2026-85102 has been available since September 9, and customers who have applied it are already protected. CVE-2026-93616 is a...

Recent mention · The Hacker News

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

The Hacker News · 22 Sep 2026

Swati KhandelwalSep 22, 2026Network Security / Vulnerability Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point gateways it manages. Separately, Check Point said attackers have been trying since September 12 to exploit a VPN flaw it fixed on September 9....

Recent mention · BleepingComputer

New Check Point flaw lets hackers execute code with root privileges

BleepingComputer · 18 Sep 2026

Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. [...]

Recent mention · Arctic Wolf

Check Point VPN Critical RCE Vulnerabilities CVE-2026-85102 & CVE-2026-85103

Arctic Wolf · 14 Sep 2026

Threat Summary Patches have now been released addressing two critical vulnerabilities: CVE-2026-85102, which affects Security Gateway and Spark Firewall, and CVE-2026-85103, which affects Security Gateway, Management Server, and Spark Firewall. CVE-2026-85102 is an improper certificate validation during VPN negotiation and CVE-2026-85103 heap overflow in ASN.1 certificate decoding. Both bugs open the door to unauthenticated remote ... Check Point VPN Critical RCE Vulnerabilities CVE-2026-85102 & CVE-2026-85103

Recent mention · BleepingComputer

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

BleepingComputer · 12 Sep 2026

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]

Recent mention · NCSC Security Advisories

NCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN producten

NCSC Security Advisories · 10 Sep 2026

Check Point heeft 2 kritieke kwetsbaarheden verholpen. De kwetsbaarheid met kenmerk CVE-2026-85102 heeft een CVSS-score van 9,8. De kwetsbaarheid bevindt zich in het VPN-onderhandelingsproces van de Quantum Security Gateway en wordt veroorzaakt door onjuiste validatie van certificaatvertrouwen. Hierdoor kan een niet-geauthenticeerde externe aanvaller authenticatiecontroles omzeilen en willekeurige code uitvoeren op de Security Gateway. Exploitatie vindt plaats tijdens de VPN-onderhandeling, waarbij certificaatgegevens onvoldoende worden gevalideerd. De kwetsbaarheid geldt voor Security...

Recent mention · CERT Polska

Krytyczne podatności w produktach firmy Check Point

CERT Polska · 10 Sep 2026

Zespół CERT Polska informuje o krytycznych podatnościach w produktach firmy Check Point.Podatności, oznaczone jako CVE-2026-85102 oraz CVE-2026-85103, umożliwiają atakującemu zdalne wykonanie dowolnego kodu na urządzeniu. Dotyczą one produktów: Security Gateway, Security Management Server oraz Check Point Spark Firewall.Rekomendujemy niezwłoczną instalację aktualizacji:LivePatch dla wersji R81.20, R82 oraz R82.10 - jeśli włączona jest jego automatyczna instalacja, łatka powinna wgrać się automatycznie,Jumbo Hotfix Accumulator: R82.10 (od Take 44), R82 (od Take 126) oraz R81.20 (od Take...

Timeline

From disclosure to observed exploitation

  1. 08:20 UTC

    KEV confirmed by SOCRadar

    Exploitation attested by an external source

  2. 05:20 UTC

    KEV confirmed by Qualys ThreatPROTECT

    Exploitation attested by an external source

  3. 21:21 UTC

    KEV confirmed by Security Affairs

    Exploitation attested by an external source

  4. 20:01 UTC

    KEV confirmed by CVE

    Exploitation attested by an external source

  5. 19:50 UTC

    Added to CISA KEV

    Listed in the CISA Known Exploited Vulnerabilities catalog

  6. 13:49 UTC

    Added to Previdian KEV Feed

    High-confidence, third-party attested exploitation

  7. 08:20 UTC

    Added to the Previdian watchlist

    Pro and Enterprise Watch users had 1 week of early warning before CISA KEV. Also 1 week before Previdian confirmed it as a KEV.

  8. 13:00 UTC

    CVE published

    Vulnerability disclosed publicly

  9. 06:38 UTC

    CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2026-85102

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2026-85102",
  "confidence": "Confirmed",
  "cvss_score": 9.8,
  "cvss_estimated": false,
  "epss_score": 0.07546,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": false
  },
  "sensor_telemetry": { "attempts": 0, "sensors": 0 }
}