CVE-2026-85102
Improper Certificate Validation in Quantum Security Gateway
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
Coverage 2 sources
-
2026-09-22
CISA Cybersecurity Advisories
high
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA added four new vulnerabilities to its Known Exploited Vulnerabilities Catalog, indicating active exploitation.
-
2026-09-23
Help Net Security
critical
Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
Check Point releases emergency fixes for critical Management Server vulnerability exploited since July 23, 2026.
Mentioned with
CVE-2026-93616 CVE-2026-93952 CVE-2026-94127
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands