CVE-2026-85102
Received
Received - Intake
Improper Certificate Validation in Check Point Quantum Security Gateway
Vulnerability report for CVE-2026-85102, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-09
Last updated on: 2026-09-09
Assigner: Check Point Software Technologies Ltd.
Description
Description
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| checkpoint | quantum_security_gateway | * |
| checkpoint | security_gateway | From R80 (inc) to R82.20 (exc) |
| checkpoint | spark_firewall | From R80 (inc) to R82.20 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-295 | The product does not validate, or incorrectly validates, a certificate. |