EUVD Vulnerability Catalog Actively Exploited (KEV)

EUVD-2026-75009

Severity: CRITICAL Base Score: 9.8 CVSS Version: 3.1

Vulnerability Description

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

▪ Attack Vector (AV): Network
▪ Attack Complexity (AC): Low
▪ Privileges Required (PR): None
▪ User Interaction (UI): None
▪ Scope (S): Unchanged
▪ Confidentiality Impact (C): High
▪ Integrity Impact (I): High
▪ Availability Impact (A): High

Affected Vendors & Systems

Vendor checkpoint

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

checkpoint

EPSS Probability

0.99

Known Aliases
GHSA-3fvr-5gg9-225m CVE-2026-85102
Published On

2026-09-09

Last Updated

2026-09-23

Exploited Since

2026-09-22