CVE-2026-85102

Summary

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Affected Software

VendorProductVersion RangeStatus
checkpointQuantum Security GatewayR82.10 with Jumbo Hotfix Take 43 or belowaffected
checkpointQuantum Security GatewayR82 with Jumbo Hotfix Take 125 or belowaffected
checkpointQuantum Security GatewayR81.20 with Jumbo Hotfix Take 165 or belowaffected

Weaknesses

  • CWE-295: CWE-295: Improper Certificate Validation.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References