← All CVEs NewScan detects
criticalKEV

CVE-2026-85102

Check Point Quantum Security Gateway improper certificate trust validation during VPN negotiation -> unauthenticated RCE

Severity
critical
Affected product
Check Point Security Gateway
Affected versions
Check Point Security Gateway all versions before the fix
CISA KEV
Listed as a known exploited vulnerability
EPSS
2% chance of exploitation in the next 30 days
Added to NewScan
2026-09-23
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Check Point Security Gateway appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-23 (/daily-cve), CVSS 9.8, CISA KEV, exploitation reported in the wild (BleepingComputer 2026-09-22). Not version-gated for the same reason as CVE-2026-93616, and not provable by request either: the flaw is in IKE/IPsec certificate validation, which is a UDP:500 negotiation this scanner does not speak - the `bypass` arm is read-only HTTP GET by construction. Advisory-only is the correct ceiling here.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →