SECURITY teams are seeing active exploitation attempts against CVE-2026-85102, a critical improper certificate-validation flaw in Check Point Quantum Security Gateway products. Check Point said it was observing exploitation attempts against Check Point Spark customers globally. The vulnerability is rated CVSS 9.8 and could allow an unauthenticated remote attacker to execute arbitrary code on a Security Gateway during VPN negotiation. The article says attacks have been observed from anonymised VPN proxies, but no public proof-of-concept exploit code has been confirmed.
Affected configurations listed include R82.10 with Jumbo Hotfix Take 43 or earlier, R82 with Jumbo Hotfix Take 125 or earlier, and R81.20 with Jumbo Hotfix Take 165 or earlier. The report also says older releases from R80 through R81.10 remain vulnerable, while R82.20 is unaffected.
According to Check Point’s advisory, improper validation of certificate data during VPN negotiation may enable remote code execution; the article describes attackers supplying forged certificates during the handshake, potentially causing memory corruption in the authentication daemon.
Administrators should install Check Point LivePatch Take 26 or the latest Jumbo Hotfix Accumulator updates, following the vendor’s support guidance. Where immediate updating is not possible, the article recommends disabling VPN implied rules and restricting incoming UDP traffic on ports 500 and 4500 to trusted peer addresses.