Quantum Security Gateway VPN
CVE-2026-85102: Gateway VPN certificate flaw allows unauthenticated code execution
Improper certificate validation during VPN negotiation lets an unauthenticated attacker run code on Check Point gateways (CVSS 9.8). Check Point saw exploitation from September 12, 2026, and CISA added it to KEV.
Published Updated
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Quantum Security Gateway R82.10 with Jumbo Hotfix Take 43 or lower | R82.10 Take 44 or later, or LivePatch Take 26 |
| Quantum Security Gateway R82 with Jumbo Hotfix Take 125 or lower | R82 Take 126 or later, or LivePatch Take 26 |
| Quantum Security Gateway R81.20 with Jumbo Hotfix Take 165 or lower | R81.20 Take 166 or later, or LivePatch Take 26 |
| Quantum Security Gateway R81.10 (end of support) | R81.10 Take 190 or later |
| Spark Firewall R82.00.x | R82.00.10 Build 2325 or later |
| Spark Firewall R81.10.x | R81.10.17 Build 4968 or later |
| R82.20 | Not affected |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
The gateway doesn’t properly validate certificate data during VPN negotiation. An unauthenticated attacker on the network can send crafted certificate data and run code on the gateway. CVSS is 9.8, and the CVE record maps it to CWE-295.
A VPN gateway sits on your perimeter and is reachable from the internet by design, so this is a direct path to the edge device. Check Point shipped fixes on September 9 with no known exploitation. Exploitation attempts began on September 12, against Spark customers first, and CISA added the CVE to KEV on September 22 (federal due date September 25). Ransomware use is listed as unknown.
Check Point’s advisory also covers CVE-2026-93616, an unrelated pre-authentication bug in the management web service. The public advisory doesn’t say the two were chained. The Dutch NCSC also warned about a related VPN certificate bug, CVE-2026-85103 (a heap overflow in the ASN.1 decoder, sk1000118). Patch for both.
No public proof of concept had been reported as of the BleepingComputer coverage.
Am I affected?
You’re affected if you run a Security Gateway or Spark Firewall (centrally or locally managed) with Site-to-Site VPN or Remote Access VPN enabled, on one of these (CVE record and Check Point):
- R82.10 with Jumbo Hotfix Take 43 or lower
- R82 with Take 125 or lower
- R81.20 with Take 165 or lower
- R81.10 and older end-of-support releases
- Spark Firewall on R82.00.x or R81.10.x below the fixed builds
R82.20 is not affected, according to the Dutch NCSC.
Check Point lists LivePatch as a fix on R81.20, R82 and R82.10. To verify its status, run this in expert mode:
cpinfo -y CPupdates
Some customers who installed an earlier offline LivePatch package need Take 26 for full coverage. Check Point’s sk1000117 has the exact procedure.
What to do
- Patch. Install one of:
- LivePatch Take 26 on R81.20, R82 or R82.10.
- Jumbo Hotfix R81.20 Take 166, R82 Take 126, R82.10 Take 44, or R81.10 Take 190, or later.
- Spark: R82.00.10 Build 2325 or R81.10.17 Build 4968, or later.
- Move off end-of-support releases that have no fix path. Check sk1000117 for options.
- If you can’t patch tonight, Check Point describes these mitigations (they do not apply to locally managed Spark firewalls):
- Site-to-Site VPN: disable the VPN implied rules and add explicit rules that allow UDP/500 and UDP/4500 only from your known peer IPs.
- Remote Access VPN: allow only the services you need (UDP/500, UDP/4500, TCP/443, and TCP/80 where applicable) and restrict source client IP ranges where you can.
- Production impact: roaming users on unknown source addresses may lose access if you restrict ranges.
- If the gateway was exposed after September 9 and unpatched, hunt using the section below. If you find signs of compromise, treat the gateway as breached: rebuild it, and rotate VPN, admin and any other credentials and keys stored on it. Also hunt for internal scanning and lateral movement.
Detection
Check Point published limited indicators. Search back to at least September 9, 2026 (earliest observed attempts: September 12):
- Certificate-based Mobile Access logins that look wrong. Check Point’s observed certificate subjects were
CN=vpn,OU=users,O=global,CN=vpn-user,OU=users,O=globalandCN=vpnuser,OU=users,O=global. The list is not exhaustive, so review all unusual certificate logins, not only these. - Second-stage activity from suspicious logged-in Mobile Access users. Check Point says it often includes internal port and service scanning.
- Connections from VPN services, proxies and other anonymization infrastructure.
No IP addresses, file hashes or file paths have been published in the sources we opened.
Indicators of compromise
Check Point says the certificate subject list is not exhaustive. It published no IP addresses, hashes or file paths in the advisory we read. Attempts came from VPN services and proxies, so source IPs are of little use.
| Indicator | Type | Reported by |
|---|---|---|
| CN=vpn,OU=users,O=global | Account nameCertificate subject seen in exploitation attempts | Check Point |
| CN=vpn-user,OU=users,O=global | Account nameCertificate subject seen in exploitation attempts | Check Point |
| CN=vpnuser,OU=users,O=global | Account nameCertificate subject seen in exploitation attempts | Check Point |
Sources
Page changelog
- Full analysis published.
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.