Critical 9.8 Actively Exploited

Check Point Quantum VPN RCE exploited in the wild (CVE-2026-85102)

CVE-2026-85102

By Yazoul AI · automated

CVE-2026-85102: unauthenticated remote code execution on Check Point Quantum Security Gateways during VPN negotiation (CVSS 9.8). Confirmed exploited; patch now.

Actively exploited in the wild - CVE-2026-85102 is a critical remote code execution vulnerability in Check Point Quantum Security Gateway VPN negotiation that grants unauthenticated attackers full code execution on the Gateway. CISA has added it to the Known Exploited Vulnerabilities catalog, confirming real-world attacks; apply the vendor hotfix immediately.

Overview

CVE-2026-85102 stems from improper certificate trust validation during the VPN negotiation process on Check Point Quantum Security Gateways. When a remote peer initiates a VPN session, the Gateway is supposed to validate the certificate chain presented by the peer before proceeding. Due to a logic error in that validation, the Gateway can be tricked into accepting a certificate it should reject.

Because the flaw is reachable before authentication completes, an attacker needs no credentials and no user interaction. They only need network access to the Gateway’s VPN endpoint, which is typically exposed to the internet. The CVSS base score of 9.8 reflects the worst-case combination: network attack vector, low complexity, no privileges, and no user interaction.

Impact

Successful exploitation lets an unauthenticated remote attacker execute arbitrary code on the Gateway. That is a severe outcome for a perimeter device: the Gateway sits at the boundary between the public internet and internal networks, and it holds VPN keys, tunnel configurations, and often directory integration credentials.

An attacker who gains code execution could intercept or decrypt VPN traffic, pivot into internal networks, or establish persistence on the appliance. Given the Gateway’s role, exploitation of a single device can expose an entire organization’s remote-access infrastructure. Organizations running internet-facing Quantum Security Gateways should treat any unexplained VPN activity as potentially hostile and review logs for unusual certificate negotiation attempts.

Remediation and Mitigation

Check Point has released a hotfix for affected Quantum Security Gateway versions. The definitive guidance is in the vendor’s advisory, which lists the exact builds that require the fix and the upgrade path for each. Apply it as soon as possible; this is not a candidate for a normal maintenance window given confirmed exploitation.

Where immediate patching is not possible, reduce exposure by restricting VPN endpoint access to known IP ranges, disabling unused VPN communities, and enforcing certificate pinning or mutual TLS where the deployment supports it. Monitor Gateway logs for repeated failed certificate negotiations from unexpected sources, and enable verbose logging on the VPN daemon temporarily to catch exploitation attempts.

After patching, rotate any credentials or pre-shared keys stored on the Gateway and review VPN peer configurations for unauthorized additions. Data breach reports are available at breach reports and ongoing coverage at security news if you suspect compromise.

Security Insight

This is the second time in recent years that a perimeter VPN appliance has been exploited in the wild through a certificate validation failure during negotiation - the pattern echoes earlier attacks on SSL VPN concentrators from other vendors, where trust-check logic was the weak link rather than memory corruption. It reinforces that certificate validation on internet-facing gateways deserves the same scrutiny as cryptographic code. For Check Point, the rapid CISA KEV listing signals that exploitation is already commodity-level, not theoretical, and that the window between patch release and mass scanning is effectively zero.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Related Advisories

Related Across Yazoul

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.