# Check Point Quantum VPN vulnerabilities

> Live situation record from CLSTR: https://clstr.news/situations/check-point-quantum-vpn-vulnerabilities
> Updated: 2026-09-12T18:49:27.000Z. Sources: 5. Developments: 2.

Check Point disclosed two critical vulnerabilities in its Quantum VPN infrastructure, identified as CVE-2026-85102 and CVE-2026-85103. Both flaws received a CVSS score of 9.8 and could allow unauthenticated remote attackers to execute arbitrary code during the VPN negotiation phase.

CVE-2026-85102 involves a failure to properly validate certificate trust in Security Gateways, while CVE-2026-85103 is a heap-based buffer overflow affecting both Security Gateways and the Security Management Server. Check Point discovered the vulnerabilities internally and reported no evidence of active exploitation in the wild. The company began releasing patches for affected Quantum branches on September 9.

## Timeline

### 2026-09-12: Check Point and Citrix issue patches for critical security vulnerabilities

Critical vulnerabilities in Check Point VPN products and Citrix NetScaler deployments are being addressed, with active exploitation reported in Citrix environments.

4 sources. https://clstr.news/cluster/check-point-and-citrix-issue-patches-for-critical-security-vulnerabilities

### 2026-09-09: Check Point patches two critical VPN certificate vulnerabilities

Check Point has patched two critical 9.8-rated vulnerabilities in its Quantum VPN infrastructure that could allow unauthenticated remote code execution.

2 sources. https://clstr.news/cluster/check-point-patches-two-critical-vpn-certificate-vulnerabilities

---
Cite as: Check Point Quantum VPN vulnerabilities. CLSTR, https://clstr.news/situations/check-point-quantum-vpn-vulnerabilities
