Quantum Security Gateway
Improper certificate trust validation in VPN negotiation allows unauthenticated RCE on Check Point Quantum Security Gateway (CVE-2026-85102)
A public write-up with a request-level proof of concept is available and the Dutch NCSC warned on 2026-09-12 that it expects exploitation attempts soon; no attacks are confirmed, but an internet-facing gateway left on an old Jumbo Hotfix take can be fully compromised without credentials once attempts start.
Check Point Quantum Security Gateway fails to properly validate certificate trust during VPN negotiation, allowing an unauthenticated remote attacker to execute arbitrary code on the gateway. The flaw sits in the VPN service that these gateways expose to the internet.
Affected: Quantum Security Gateway R82.10 with Jumbo Hotfix Take 43 or below; Quantum Security Gateway R82 with Jumbo Hotfix Take 125 or below; Quantum Security Gateway R81.20 with Jumbo Hotfix Take 165 or below
On every gateway, record the major release (R81.20, R82, R82.10) and the installed Jumbo Hotfix Accumulator Take; R82.10 at Take 43 or below, R82 at Take 125 or below, and R81.20 at Take 165 or below are affected. No in-the-wild indicators are published yet, so review VPN negotiation and daemon logs for certificate exchanges from untrusted or unexpected sources, and check gateways reachable since 2026-09-09 for unexpected processes, accounts, or configuration changes.
Install the Jumbo Hotfix Accumulator referenced in Check Point advisory sk1000117: a take above 43 for R82.10, above 125 for R82, and above 165 for R81.20. Until the hotfix is applied, limit which source addresses can reach the gateway's VPN endpoints.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
