Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 5 sources · 3 days · First seen · Last updated
Check Point Quantum VPN vulnerabilities
Overview
Check Point disclosed two critical vulnerabilities in its Quantum VPN infrastructure, identified as CVE-2026-85102 and CVE-2026-85103. Both flaws received a CVSS score of 9.8 and could allow unauthenticated remote attackers to execute arbitrary code during the VPN negotiation phase.
CVE-2026-85102 involves a failure to properly validate certificate trust in Security Gateways, while CVE-2026-85103 is a heap-based buffer overflow affecting both Security Gateways and the Security Management Server. Check Point discovered the vulnerabilities internally and reported no evidence of active exploitation in the wild. The company began releasing patches for affected Quantum branches on September 9.
Entities
Timeline
-
[TECHNOLOGY] 4 sourcesCheck Point and Citrix issue patches for critical security vulnerabilities
Critical vulnerabilities in Check Point VPN products and Citrix NetScaler deployments are being addressed, with active exploitation reported in Citrix environments.
-
[TECHNOLOGY] 2 sourcesCheck Point patches two critical VPN certificate vulnerabilities
Check Point has patched two critical 9.8-rated vulnerabilities in its Quantum VPN infrastructure that could allow unauthenticated remote code execution.
Sources
cybernoz.com · dev.to · flagthis.com · forkast.news · security-insider.de