CVE-2026-85102 is a critical failure to properly validate certificate trust during VPN negotiation in Check Point Security Gateway firewall appliances, rated CVSS 9.8 by the vendor. An unauthenticated remote attacker may be able to execute code on the Security Gateway, though Check Point says this occurs only "under specific conditions" that it has not described. It was disclosed to Check Point's customer community on 9 September 2026 and fixes began shipping the same day via Live Patch and the Jumbo Hotfix channel.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-85102 |
| CVSS | 9.8 (vendor-assigned) |
| Type | Improper certificate trust validation during VPN negotiation |
| Affected | R82.10 (Jumbo Hotfix Take 43 or below), R82 (Take 125 or below), R81.20 (Take 165 or below) |
| Advisories | Check Point sk1000117 / sk1000118; Canadian Centre for Cyber Security advisory |
| Exploited | No indication of exploitation as at 2026-09-10 |
Check Point found both this flaw and CVE-2026-85103 itself, and has published no indicators of compromise, noting that indicators only apply where exploits already exist. The affected-version list covers only three Quantum branches; the Canadian Centre for Cyber Security advisory lists a broader product set including Spark Firewall but gives no versions at all. See also CVE-2026-85103, and CVE-2026-50751 and CVE-2026-16232, Check Point flaws from June and July 2026 that were already being exploited at disclosure.