Skip to content
Critical RCE Vulnerabilities in Check Point Quantum Security Gateway

Critical RCE Vulnerabilities in Check Point Quantum Security Gateway

First seen 14 Sep 2026, 01:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 02:58 UTC
  • Two critical RCE vulnerabilities (CVE-2026-85102, CVE-2026-85103) in Check Point Quantum Security.
  • Public proof-of-concept code is available, increasing the risk of exploitation.
  • Immediate patching is required for affected systems to prevent potential breaches.

Two critical vulnerabilities (CVE-2026-85102 and CVE-2026-85103) have been identified in Check Point Quantum Security Gateway, allowing unauthenticated remote code execution (RCE). Both vulnerabilities stem from improper handling of VPN certificate ASN.1 decoding and trust validation. The Dutch NCSC issued an alert on September 12, 2026, warning of expected exploitation attempts, although no attacks have been confirmed yet. Affected systems include various versions of Quantum Security Gateway and Management with specific Jumbo Hotfix Accumulator Takes. Administrators are advised to apply the necessary hotfixes immediately to mitigate the risk of exploitation. The vulnerabilities are critical, with a CVSS score of 9.8, indicating a high potential impact if exploited. Monitoring logs for unusual activity is also recommended until patches are applied.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-09
CVE-2026-85102 and CVE-2026-85103 published
Check Point disclosed two critical vulnerabilities affecting Quantum Security Gateway and Management systems.
Buttondown
2026-09-12
Dutch NCSC issues alert
The Dutch NCSC warned of expected exploitation attempts for the identified vulnerabilities.
Buttondown
Recent
Public PoC released
A public write-up with a request-level proof of concept for both vulnerabilities has been made available.
exploitbulletin.com

More articles in this cluster (4)

Following this threat?

Track Check Point and CVE-2026-85102 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed