CVE-2026-85102: Check Point Multiple Products Improper Certificate Validation Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-09-22. EPSS: 7.5% chance of exploitation in the next 30 days.
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
Affected products
- Check Point Gaia Embedded: from r81.10.00, before r81.10.17 (fixed in r81.10.17); from r82.00.00, before r82.00.10 (fixed in r82.00.10); version r81.10.17 only; version r82.00.10 only
- Check Point Gaia OS: from r80, before r81.10 (fixed in r81.10); version r81.10 only; version r81.20 only; version r82 only; version r82.10 only
Published 2026-09-09. Last modified 2026-09-23.