{"id":"CVE-2026-85102","title":"Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.","summary":"Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-295"],"vendor":"checkpoint","product":"Quantum Security Gateway","affected":["quantum_security_gateway R82.10 with Jumbo Hotfix Take 43 or below","quantum_security_gateway R82 with Jumbo Hotfix Take 125 or below","quantum_security_gateway R81.20 with Jumbo Hotfix Take 165 or below"],"published":"2026-09-09","updated":"2026-09-23","sourceUpdated":"2026-09-23T04:17:56.393","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85102","references":[{"url":"https://support.checkpoint.com/results/sk/sk1000117","label":"cve@checkpoint.com"},{"url":"https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85102","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","cve.org","exploit-available"],"epss":0.00329,"epssPercentile":0.26293,"kev":true,"kevDateAdded":"2026-09-22","kevDueDate":"2026-09-25","kevRansomware":false,"exploited":true,"exploitAvailable":true,"ssvc":{"exploitation":"active","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-22T19:40:15.351905Z"},"ingestedAt":"2026-09-14T14:05:09.307Z","slug":"CVE-2026-85102","body":"## Overview\n\nImproper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"hadal","depthScore":79,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":25,"ransomware":0},"changes":[{"seq":209467,"id":"CVE-2026-85102","ts":1790140672261,"field":"kev","old":"false","new":"true"},{"seq":209368,"id":"CVE-2026-85102","ts":1790107892484,"field":"exploit_available","old":"false","new":"true"},{"seq":209367,"id":"CVE-2026-85102","ts":1790107892484,"field":"exploited","old":"false","new":"true"}]}