Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4892 articles · 221245 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-85102KEVEXPLOITED
checkpoint · quantum security gateway

Improper Certificate Validation in Quantum Security Gateway

Description

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Affected Products

VendorProductVersions
checkpointquantum security gatewayR82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, R81.20 with Jumbo Hotfix Take 165 or below

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
check pointsparkcert_advisory90%
check pointsecuritycert_advisory90%
check pointsecurity managementcert_advisory90%

References

  • https://support.checkpoint.com/results/sk/sk1000117

Related News (10 articles)

Tier D
Heise Security2h ago
Cyberangriffe auf F5 BIG-IP, Check Point Security und Arista VeloCloud
→ No new info (linked only)
Tier D
SecurityWeek2h ago
Check Point Patches Exploited Management Server Zero-Day
→ No new info (linked only)
Tier D
BleepingComputer10d ago
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
→ No new info (linked only)
Tier D
Heise Security11d ago
Patches: IT-Sicherheitsprodukte von Check Point werden zum Sicherheitsrisiko
→ No new info (linked only)
Tier D
SecurityWeek11d ago
Check Point Patches Critical VPN Vulnerabilities
→ No new info (linked only)
Tier B
BSI Advisories12d ago
[NEU] [hoch] Check Point Security Gateway, Spark Firewall und Security Management: Mehrere Schwachstellen ermöglichen Codeausführung
→ No new info (linked only)
Tier D
The Hacker News12d ago
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
→ No new info (linked only)
Tier B
CERT-FR13d ago
Multiples vulnérabilités dans les produits Check Point (10 septembre 2026)
→ No new info (linked only)
Tier B
CCCS Canada13d ago
Check Point security advisory (AV26-902)
→ No new info (linked only)
Tier C
VulDB13d ago
CVE-2026-85102 | Check Point Quantum Security Gateway VPN negotiation certificate validation
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
CWECWE-295
PublishedSep 9, 2026
Trending Score162🔥
Source articles10
Independent8
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-93616EXPKEV
Directory Traversal and File upload allows execution of arbitrary script on the Management Server
Trending: 148
NONECVE-2026-16232EXP
Authentication Bypass in the SmartConsole Login Process Using an Application Token
Trending: 102
CRITICALCVE-2026-91843
Stack overflow in login process to the Security Management and Log Servers
Trending: 59
CRITICALCVE-2026-85103
Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding
Trending: 46
CRITICALCVE-2026-62144
Management Authentication Bypass and Privilege Escalation
Trending: 37

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 9, 2026
Added to CISA KEV
Sep 9, 2026
Discovered by ZDM
Sep 9, 2026
Actively Exploited
Sep 23, 2026