CVE-2026-85102 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 1% (pctl 61)
Patch first
On CISA KEV — known exploited in the wild, due 2026-09-25.
Description
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.99% — more likely to be exploited than 61% of all CVEs |
| Weakness | CWE-295 |
| On CISA KEV | yes — remediate by 2026-09-25 |
| Public exploit | none known |
| Published | 2026-09-09 |
| Last modified | 2026-09-23 |
CISA KEV
| Name | Check Point Multiple Products Improper Certificate Validation Vulnerability |
|---|---|
| Added | 2026-09-22 |
| Due | 2026-09-25 |
| Vendor / product | Check Point / Multiple Products |
| Ransomware use | none reported |
Affected (40)
| Vendor | Product |
|---|---|
| checkpoint | gaia embedded |
| checkpoint | gaia os |
| checkpoint | quantum 3600 |
| checkpoint | quantum 3800 |
| checkpoint | quantum force 19100 |
| checkpoint | quantum force 19200 |
| checkpoint | quantum force 29100 |
| checkpoint | quantum force 29200 |
| checkpoint | quantum force 3920 |
| checkpoint | quantum force 3950 |
| checkpoint | quantum force 3970 |
| checkpoint | quantum force 3980 |
| checkpoint | quantum force 9100 |
| checkpoint | quantum force 9200 |
| checkpoint | quantum force 9300 |
| checkpoint | quantum force 9400 |
| checkpoint | quantum force 9700 |
| checkpoint | quantum force 9800 |
| checkpoint | quantum lightspeed mls200 |
| checkpoint | quantum spark 1530 |
| checkpoint | quantum spark 1535 |
| checkpoint | quantum spark 1550 |
| checkpoint | quantum spark 1555 |
| checkpoint | quantum spark 1570 |
| checkpoint | quantum spark 1570r |
| checkpoint | quantum spark 1575 |
| checkpoint | quantum spark 1575r |
| checkpoint | quantum spark 1590 |
| checkpoint | quantum spark 1595 |
| checkpoint | quantum spark 1595r |
| checkpoint | quantum spark 1600 |
| checkpoint | quantum spark 1800 |
| checkpoint | quantum spark 1900 |
| checkpoint | quantum spark 2000 |
| checkpoint | quantum spark 2530 |
| checkpoint | quantum spark 2550 |
| checkpoint | quantum spark 2560 |
| checkpoint | quantum spark 2570 |
| checkpoint | quantum spark 2580 |
| checkpoint | quantum spark 2590 |
References
- https://support.checkpoint.com/results/sk/sk1000117
- https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85102
→ the Explorer · watch your stack · NVD