CVE-2026-85103 is a critical heap-based buffer overflow in Check Point software that occurs while the product decodes the ASN.1 structure of a VPN certificate, rated CVSS 9.8 by the vendor. An unauthenticated remote attacker may be able to execute code on Check Point Quantum Security Management and Quantum Security Gateway systems, though Check Point says this occurs only "under specific conditions" that it has not described. It was disclosed to Check Point's customer community on 9 September 2026 with fixes shipping the same day.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-85103 |
| CVSS | 9.8 (vendor-assigned) |
| Type | Heap-based buffer overflow during ASN.1 VPN certificate decoding |
| Affected | R82.10 (Jumbo Hotfix Take 43 or below), R82 (Take 125 or below), R81.20 (Take 165 or below) |
| Advisories | Check Point sk1000117 / sk1000118; Canadian Centre for Cyber Security advisory |
| Exploited | No indication of exploitation as at 2026-09-10 |
Asked in Check Point's own community thread whether gateways with the VPN software blade disabled remain affected, a vendor staff member replied that the issue concerns certificate processing, so it could in theory be triggered in an environment without VPN enabled but with VPN certificates present. Customers on the R81.10 branch reported in the same thread that neither Live Patch nor a Jumbo Hotfix was available to them, leaving the advisory's vaguely worded VPN implied-rules mitigation as the only option. See also CVE-2026-85102 and CVE-2026-16232.