Vulnerability Intelligence Report
Improper Certificate Validation in Quantum Security Gateway
CVE-2026-85102
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-295 ↗CWE-295: Improper Certificate Validation.
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| checkpoint | Quantum Security Gateway | R82.10 with Jumbo Hotfix Take 43 or below (affected), R82 with Jumbo Hotfix Take 125 or below (affected), R81.20 with Jumbo Hotfix Take 165 or below (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Check Point Software Ltd. · Vendor · Israel |
| Reserved | 2026-09-03T06:38:15 |
| Published | 2026-09-09T13:00:31 |
| Last Updated | 2026-09-10T03:56:43 |
Community Chatter & Buzz