CVE-2026-85102
Check Point Quantum Security Gateway improper certificate trust validation during VPN negotiation -> unauthenticated RCE
- Severity
- critical
- Affected product
- Check Point Security Gateway
- Affected versions
- Check Point Security Gateway all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- EPSS
- 2% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-09-23
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Check Point Security Gateway appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-23 (/daily-cve), CVSS 9.8, CISA KEV, exploitation reported in the wild (BleepingComputer 2026-09-22). Not version-gated for the same reason as CVE-2026-93616, and not provable by request either: the flaw is in IKE/IPsec certificate validation, which is a UDP:500 negotiation this scanner does not speak - the `bypass` arm is read-only HTTP GET by construction. Advisory-only is the correct ceiling here.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →