Back

CRITICAL KEV

Improper Certificate Validation in Quantum Security Gateway

Published Sep 9, 2026 ·Due Sep 25, 2026

Description

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (3)

Change history (9)
  1. CISA ADP
    • SSVC exploitation changed from none to active
  2. CISA ADP
    • SSVC exploitation changed from active to none
  3. CISA ADP
    • SSVC exploitation changed from none to active
  4. CISA ADP
    • SSVC exploitation changed from active to none
  5. CISA ADP
    • SSVC exploitation changed from none to active
  6. CISA ADP
    • SSVC exploitation changed from active to none
  7. CISA ADP
    • SSVC exploitation changed from none to active
  8. CISA ADP
    • SSVC exploitation changed from active to none
  9. CISA ADP
    • SSVC exploitation changed from none to active
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner checkpoint
Published Sep 9, 2026
Updated Sep 23, 2026
Reserved Sep 3, 2026
CISA Vulnrichment
Updated Sep 22, 2026
NVD
Status Awaiting Analysis
Modified Sep 22, 2026
Red Hat
Severity n/a
Public date n/a