Quantum Security Gateway VPN

CVE-2026-85102: Gateway VPN certificate flaw allows unauthenticated code execution

Improper certificate validation during VPN negotiation lets an unauthenticated attacker run code on Check Point gateways (CVSS 9.8). Check Point saw exploitation from September 12, 2026, and CISA added it to KEV.

Published Updated

ExploitedYes, in CISA KEVAdded 22 Sept 2026
Ransomware useNot reportedPer CISA
SeverityCRITICALCVSS 3.1 9.8
EPSS7.5%Chance of exploitation in 30 days
Public exploitNot known
FixAvailable

Affected and fixed versions

Product / branchFixed in
Quantum Security Gateway R82.10 with Jumbo Hotfix Take 43 or lowerR82.10 Take 44 or later, or LivePatch Take 26
Quantum Security Gateway R82 with Jumbo Hotfix Take 125 or lowerR82 Take 126 or later, or LivePatch Take 26
Quantum Security Gateway R81.20 with Jumbo Hotfix Take 165 or lowerR81.20 Take 166 or later, or LivePatch Take 26
Quantum Security Gateway R81.10 (end of support)R81.10 Take 190 or later
Spark Firewall R82.00.xR82.00.10 Build 2325 or later
Spark Firewall R81.10.xR81.10.17 Build 4968 or later
R82.20Not affected

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

The gateway doesn’t properly validate certificate data during VPN negotiation. An unauthenticated attacker on the network can send crafted certificate data and run code on the gateway. CVSS is 9.8, and the CVE record maps it to CWE-295.

A VPN gateway sits on your perimeter and is reachable from the internet by design, so this is a direct path to the edge device. Check Point shipped fixes on September 9 with no known exploitation. Exploitation attempts began on September 12, against Spark customers first, and CISA added the CVE to KEV on September 22 (federal due date September 25). Ransomware use is listed as unknown.

Check Point’s advisory also covers CVE-2026-93616, an unrelated pre-authentication bug in the management web service. The public advisory doesn’t say the two were chained. The Dutch NCSC also warned about a related VPN certificate bug, CVE-2026-85103 (a heap overflow in the ASN.1 decoder, sk1000118). Patch for both.

No public proof of concept had been reported as of the BleepingComputer coverage.

Am I affected?

You’re affected if you run a Security Gateway or Spark Firewall (centrally or locally managed) with Site-to-Site VPN or Remote Access VPN enabled, on one of these (CVE record and Check Point):

  • R82.10 with Jumbo Hotfix Take 43 or lower
  • R82 with Take 125 or lower
  • R81.20 with Take 165 or lower
  • R81.10 and older end-of-support releases
  • Spark Firewall on R82.00.x or R81.10.x below the fixed builds

R82.20 is not affected, according to the Dutch NCSC.

Check Point lists LivePatch as a fix on R81.20, R82 and R82.10. To verify its status, run this in expert mode:

cpinfo -y CPupdates

Some customers who installed an earlier offline LivePatch package need Take 26 for full coverage. Check Point’s sk1000117 has the exact procedure.

What to do

  1. Patch. Install one of:
    • LivePatch Take 26 on R81.20, R82 or R82.10.
    • Jumbo Hotfix R81.20 Take 166, R82 Take 126, R82.10 Take 44, or R81.10 Take 190, or later.
    • Spark: R82.00.10 Build 2325 or R81.10.17 Build 4968, or later.
  2. Move off end-of-support releases that have no fix path. Check sk1000117 for options.
  3. If you can’t patch tonight, Check Point describes these mitigations (they do not apply to locally managed Spark firewalls):
    • Site-to-Site VPN: disable the VPN implied rules and add explicit rules that allow UDP/500 and UDP/4500 only from your known peer IPs.
    • Remote Access VPN: allow only the services you need (UDP/500, UDP/4500, TCP/443, and TCP/80 where applicable) and restrict source client IP ranges where you can.
    • Production impact: roaming users on unknown source addresses may lose access if you restrict ranges.
  4. If the gateway was exposed after September 9 and unpatched, hunt using the section below. If you find signs of compromise, treat the gateway as breached: rebuild it, and rotate VPN, admin and any other credentials and keys stored on it. Also hunt for internal scanning and lateral movement.

Detection

Check Point published limited indicators. Search back to at least September 9, 2026 (earliest observed attempts: September 12):

  • Certificate-based Mobile Access logins that look wrong. Check Point’s observed certificate subjects were CN=vpn,OU=users,O=global, CN=vpn-user,OU=users,O=global and CN=vpnuser,OU=users,O=global. The list is not exhaustive, so review all unusual certificate logins, not only these.
  • Second-stage activity from suspicious logged-in Mobile Access users. Check Point says it often includes internal port and service scanning.
  • Connections from VPN services, proxies and other anonymization infrastructure.

No IP addresses, file hashes or file paths have been published in the sources we opened.

Indicators of compromise

Check Point says the certificate subject list is not exhaustive. It published no IP addresses, hashes or file paths in the advisory we read. Attempts came from VPN services and proxies, so source IPs are of little use.

IndicatorTypeReported by
CN=vpn,OU=users,O=globalAccount nameCertificate subject seen in exploitation attemptsCheck Point
CN=vpn-user,OU=users,O=globalAccount nameCertificate subject seen in exploitation attemptsCheck Point
CN=vpnuser,OU=users,O=globalAccount nameCertificate subject seen in exploitation attemptsCheck Point

Sources

Page changelog

  • Full analysis published.

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.