T
Threats
Check Point Quantum Security Gateway Critical VPN Vulnerability
Overview
CVE: CVE-2026-85102
Severity: Critical
CVSS: 9.8
Advisory updated: 9 September 2026
Check Point has disclosed a critical vulnerability in VPN negotiation that affects Security Gateways and Check Point Spark Firewalls using Site-to-Site VPN or Remote Access VPN. Improper validation of certificate data may allow an unauthenticated remote attacker to execute arbitrary code on an affected Security Gateway.
Affected Versions
Check Point Security Gateway and Spark Firewall
Affected: R81.20, R82, R82.10, R80, R80.10, R80.20, R80.30, R80.40, R81 and R81.10, including R81.10.x and R82.00.x. Check Point identifies the R80 through R81.10 base releases as end of support.
Fixed: Check Point states that the issue has been fixed. For applicable R81.20 and R82 deployments, Check Point directs administrators to validate the
BUNDLE_URGENT_SECURITY_UPDATE_R81_20_AUTOUPDATEorBUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATELivePatch bundle, Take 24.Not affected: R82.20.
Vulnerability Breakdown
CVE-2026-85102 - Improper certificate validation in VPN negotiation
Severity: Critical
CVSS: 9.8
Description: Improper validation of certificate data during VPN negotiation may permit an unauthenticated remote attacker to execute arbitrary code on a Security Gateway.
Impact: Potential arbitrary code execution on the affected gateway, placing gateway operation and the connected environment at risk.
Conditions: The advisory applies to affected Security Gateway and Spark Firewall deployments using Site-to-Site VPN or Remote Access VPN.
Notes: The Site-to-Site VPN mitigation below is not applicable to locally managed Spark Firewalls.
Mitigation
Identify affected Security Gateway and Spark Firewall deployments that use Site-to-Site VPN or Remote Access VPN.
Upgrade or apply the Check Point remediation immediately. Validate that the applicable LivePatch bundle, Take 24, is installed and active using Check Point's documented commands.
For Site-to-Site VPN, disable implied VPN rules and manually define VPN access for UDP/500 and UDP/4500 for the specific peer IP addresses.
Do not use the Site-to-Site VPN mitigation as a substitute on locally managed Spark Firewalls, as Check Point states it is not applicable to that platform.
Prioritise replacement or upgrade planning for end-of-support releases listed as affected.
Summary for IT Teams
Products: Check Point Security Gateway and Check Point Spark Firewall using Site-to-Site VPN or Remote Access VPN
Threat level: Critical, CVSS 9.8
Action required: Confirm exposure, apply Check Point's fix or LivePatch remediation, validate deployment of Take 24 where applicable, and restrict Site-to-Site VPN access to known peer IP addresses while remediation is completed.
References
Need Help?
Secure ISS can help assess affected Check Point VPN deployments, validate remediation and support upgrade planning. Contact us on 1300 769 460 or email the Secure ISS team.

