• CISA KEV
  • EXPLOITED

CVE-2026-85102: pre-auth remote code execution in Check Point Quantum Security Gateway

An unauthenticated remote attacker can run arbitrary code on Check Point Quantum Security Gateway by exploiting improper certificate trust validation during VPN negotiation. CVE-2026-85102 affects the listed Quantum Security Gateway releases: R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, and R81.20 with Jumbo Hotfix Take 165 or below. Exploitation requires network access to the device’s VPN negotiation endpoints and does not require valid credentials or user interaction.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.07546
CWE
CWE-295
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: CISA added this flaw to its Known Exploited Vulnerabilities catalog with a rapid remediation deadline, so prioritize mitigation for internet-facing Quantum Security Gateway instances and follow vendor guidance immediately.

What is CVE-2026-85102?

An unauthenticated remote attacker can run arbitrary code on Check Point Quantum Security Gateway by exploiting improper certificate trust validation during VPN negotiation. CVE-2026-85102 affects the listed Quantum Security Gateway releases: R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, and R81.20 with Jumbo Hotfix Take 165 or below. Exploitation requires network access to the device’s VPN negotiation endpoints and does not require valid credentials or user interaction. The weakness is classified as CWE-295 (Improper Certificate Validation).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Check Point Quantum Security Gateway are affected?

BRANCHAFFECTEDFIXED
Quantum Security GatewayR82.10 with Jumbo Hotfix Take 43 or below
Quantum Security GatewayR82 with Jumbo Hotfix Take 125 or below
Quantum Security GatewayR81.20 with Jumbo Hotfix Take 165 or below

Is CVE-2026-85102 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-22, and US federal agencies were required to remediate by 2026-09-25.

How to fix CVE-2026-85102

  1. Follow Check Point vendor guidance and apply any recommended mitigations immediately.
  2. If patching is unavailable, restrict network exposure to VPN negotiation ports to trusted hosts and networks only.
  3. Disable affected VPN services or features where feasible until a vendor fix is available.
  4. Monitor gateway logs and network traffic for suspicious VPN negotiation attempts and signs of compromise.

Frequently asked questions

Is CVE-2026-85102 being actively exploited?

CISA added CVE-2026-85102 to its Known Exploited Vulnerabilities catalog on 2026-09-22, triggering a federal remediation requirement by 2026-09-25.

Which Quantum Security Gateway versions are affected by CVE-2026-85102?

Affected releases are Quantum Security Gateway R82.10 with Jumbo Hotfix Take 43 or below; R82 with Jumbo Hotfix Take 125 or below; and R81.20 with Jumbo Hotfix Take 165 or below.

Is there a patch for CVE-2026-85102?

There is no fixed version listed in the provided vendor data; follow Check Point guidance for mitigations and check for vendor updates.

Does CVE-2026-85102 require authentication?

No; the vulnerability stems from improper certificate validation during VPN negotiation and can be exploited by an unauthenticated remote attacker.

References