Critical RCE Vulnerabilities in Check Point Quantum Security Gateway
Article Content
- •Two critical RCE vulnerabilities (CVE-2026-85102, CVE-2026-85103) in Check Point Quantum Security.
- •Public proof-of-concept code is available, increasing the risk of exploitation.
- •Immediate patching is required for affected systems to prevent potential breaches.
Two critical vulnerabilities (CVE-2026-85102 and CVE-2026-85103) have been identified in Check Point Quantum Security Gateway, allowing unauthenticated remote code execution (RCE). Both vulnerabilities stem from improper handling of VPN certificate ASN.1 decoding and trust validation. The Dutch NCSC issued an alert on September 12, 2026, warning of expected exploitation attempts, although no attacks have been confirmed yet. Affected systems include various versions of Quantum Security Gateway and Management with specific Jumbo Hotfix Accumulator Takes. Administrators are advised to apply the necessary hotfixes immediately to mitigate the risk of exploitation. The vulnerabilities are critical, with a CVSS score of 9.8, indicating a high potential impact if exploited. Monitoring logs for unusual activity is also recommended until patches are applied.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Check Point and CVE-2026-85102 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…
Critical Check Point VPN Vulnerabilities Disclosed and Patched On September 9, 2026, Check Point disclosed two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both with a CVSS score of 9.8, affecting its Quantum product line. These vulnerabilities allow unauthenticated remote code execution through improper certificate trust validation and a heap-based buffer…