Vulnerability threat dossier

CVE-2026-85102

checkpointquantum 3600

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

VTP deterministic threat46.2of 100 · CVSS excluded

VTP analyst assessment

Check Point VPN negotiation RCE is actively exploited

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV

Assessment

CVE-2026-85102 affects Check Point Quantum Security Gateway VPN negotiation. Improper certificate trust validation allows an unauthenticated remote attacker to execute arbitrary code. Check Point confirmed active exploitation to BleepingComputer, and ENISA lists the flaw as known exploited.

Why it matters

  • The VPN-facing mechanism can be reachable before authentication, creating a direct gateway compromise opportunity.
  • Code execution on a security gateway can expose traffic-handling and network-control functions.

Evidence

3 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The mapped reports do not identify affected customer gateways or an exploit chain.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use affected Check Point gateways, apply the vendor's urgent remediation immediately.

AI baseline history (8)
  1. BASELINE ASSESSED
    Check Point VPN negotiation RCE is actively exploitedgpt-5.6-terra · low
  2. BASELINE ASSESSED
    Check Point Quantum Security Gateway certificate validation flawgpt-5.6-terra · low
  3. BASELINE ASSESSED
    Check Point Quantum Security Gateway certificate-validation RCEgpt-5.6-terra · low
  4. BASELINE ASSESSED
    Check Point VPN certificate-validation remote code executiongpt-5.6-terra · low
  5. BASELINE ASSESSED
    Reported Check Point VPN vulnerabilitygpt-5.6-terra · low
  6. BASELINE ASSESSED
    Check Point VPN flaw is warned as imminently exploitablegpt-5.6-terra · low
  7. BASELINE ASSESSED
    Reported Check Point VPN remote code execution riskgpt-5.6-terra · low
  8. BASELINE ASSESSED
    Check Point VPN flaw with incomplete CVE metadatagpt-5.6-terra · low
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0161th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.01; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

ACTIVE EXPLOITATIONENISA EU KEV entry added
KEV ADDEDCISA KEV entry added
CERT ADVISORYNew CERT advisory
03

Claim provenance

Evidence and source independence

11publications detected
11underlying evidence chains

2 primary sources · 0 dependent secondary reports · 9 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:90ca8d49f35b2de1fee6cbc88a1090da13a8f6d6914e7ab95a3bc37c33f948caACTIVE
Evidence
Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2026-85102ACTIVE
Evidence
Source claimURGENT PATCHINGSOURCE URGES URGENT PATCHING
62%claim confidence
UNKNOWNreport:1d67634bfd055f8b66243743993d7ccb788cb776cfcafda8a267d92a581c5a94ACTIVE
Evidence
04

Event history

Threat timeline

  1. 19:5323 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 00:0022 Sept
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. This is public intelligence, not a VTP sensor observation.

  3. 00:0022 Sept
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

  4. 09:3418 Sept
    URGENT PATCHING

    Urgent Patching

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  5. 00:0010 Sept
    CERT ADVISORY

    New CERT advisory

    CERT-FR published evidence linked to CVE-2026-85102.

05

Original publications

Source record

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]

CVE-2026-85102CVE-2026-93616
Separate evidence group
Original

InfraTrust report warns network management systems under attack

Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. [...]

CVE-2026-20079CVE-2026-20212CVE-2026-20293CVE-2026-20316CVE-2026-31431CVE-2026-33197CVE-2026-6485CVE-2026-73453CVE-2026-73456CVE-2026-76460CVE-2026-83548CVE-2026-83549CVE-2026-85102CVE-2026-85103CVE-2026-91843
Separate evidence group
Original

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point

CVE-2026-85102CVE-2026-85103CVE-2026-91843CVE-2026-93616
Separate evidence group
Original

Check Point warns of Management Server zero-day exploited in attacks

Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. [...]

CVE-2024-24919CVE-2026-16232CVE-2026-50751CVE-2026-85102CVE-2026-85103CVE-2026-93616
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2026-85102

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2026-85102
Separate evidence group
Original

New Check Point flaw lets hackers execute code with root privileges

Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. [...]

CVE-2026-16232CVE-2026-50751CVE-2026-85102CVE-2026-85103CVE-2026-91843
Separate evidence group
Original

⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of

CVE-2021-24084CVE-2021-38003CVE-2021-41379CVE-2025-20701CVE-2025-53521CVE-2026-10090CVE-2026-12645CVE-2026-12646CVE-2026-12647CVE-2026-12650CVE-2026-12744CVE-2026-12745CVE-2026-18667CVE-2026-20293CVE-2026-26084CVE-2026-33197CVE-2026-42016CVE-2026-42018CVE-2026-44756CVE-2026-50656CVE-2026-51990CVE-2026-58240CVE-2026-61578CVE-2026-61582CVE-2026-61583CVE-2026-61584CVE-2026-61585CVE-2026-61587CVE-2026-61600CVE-2026-61601CVE-2026-61602CVE-2026-6485CVE-2026-67401CVE-2026-69414CVE-2026-70647CVE-2026-70648CVE-2026-76578CVE-2026-78546CVE-2026-78547CVE-2026-81578CVE-2026-81963CVE-2026-82078CVE-2026-82329CVE-2026-82533CVE-2026-84282CVE-2026-84286CVE-2026-84388CVE-2026-84390CVE-2026-84393CVE-2026-85046CVE-2026-85102CVE-2026-85103CVE-2026-85706CVE-2026-85880CVE-2026-87491
Separate evidence group
Original

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]

CVE-2026-85102CVE-2026-85103
Separate evidence group
Original

Check Point Patches Critical VPN Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek .

CVE-2026-16232CVE-2026-50751CVE-2026-85102CVE-2026-85103
Separate evidence group
Original

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security

CVE-2026-16232CVE-2026-50751CVE-2026-85102CVE-2026-85103
Separate evidence group
Original

Multiples vulnérabilités dans les produits Check Point (10 septembre 2026)

De multiples vulnérabilités ont été découvertes dans les produits Check Point. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un contournement de la politique de sécurité.

CVE-2026-85102CVE-2026-85103
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score46.2vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction0.2 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency6 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-295
CPE records
179
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.