Check Point Pre-Auth Flaws Under Attack
Check Point says two critical pre-authentication flaws, including CVE-2026-85102, are being actively exploited.
Check Point warned that two critical pre-authentication vulnerabilities in its security products are being actively exploited. The available report identifies CVE-2026-85102 as affecting VPN certificate handling, but the text cuts off before naming the second flaw or the full product list. Because the bugs require no authentication and exploitation is already underway, exposed Check Point VPN and security appliances are an urgent patching priority.
- Check Point says two critical pre-authentication flaws are actively exploited.
- CVE-2026-85102 affects VPN certificate handling.
- The available text names only one of the two vulnerabilities.
Vulnerabilities mentionedAll →
- CVE-2026-851029.8<1%Unauthenticated RCE in Check Point Quantum Security Gateway via certificate flawpublished · Check Point Quantum Security Gateway (VPN negotiation functionality) KEV
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-85102 | Unauthenticated RCE in Check Point Quantum Security Gateway via certificate flaw CVE-2026-85102 is an improper certificate trust-validation flaw (CWE-295) in the VPN negotiation code of Check Point Quantum Security Gateways. An unauthenticated remote attacker who can reach the gateway's VPN service can trigger the flaw during VPN negotiation, where certificates involved in the exchange are not properly validated, and achieve code execution on the gateway. Successful exploitation yields arbitrary code execution on the gateway with high impact on confidentiality, integrity, and availability (CVSS 9.8), amounting to full compromise of the security gateway. The affected population is organizations running Quantum Security Gateways with VPN services reachable from untrusted networks. As of the available reporting there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation is confirmed; the issue was disclosed alongside a second, similarly rated (9.8) Check Point VPN certificate-validation RCE flaw. |
Check Point Pre-Auth Flaws Under Attack Check Point has warned that two critical, pre-authentication vulnerabilities affecting its security products are being actively exploited. CVE-2026-85102 affects VPN certificate ha
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at socradar.io.