Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-11 ยท updated: 2026-09-11 ยท tags: [cve, check-point, quantum, security-management-server, vpn, heap-overflow, asn1, rce] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, financial-services] ยท au_impact: true

CVE-2026-85103 is a critical heap-based buffer overflow in Check Point software that occurs while the product decodes the ASN.1 structure of a VPN certificate, rated CVSS 9.8 by the vendor. An unauthenticated remote attacker may be able to execute code on Check Point Quantum Security Management and Quantum Security Gateway systems, though Check Point says this occurs only "under specific conditions" that it has not described. It was disclosed to Check Point's customer community on 9 September 2026 with fixes shipping the same day.

Attribute Detail
CVE CVE-2026-85103
CVSS 9.8 (vendor-assigned)
Type Heap-based buffer overflow during ASN.1 VPN certificate decoding
Affected R82.10 (Jumbo Hotfix Take 43 or below), R82 (Take 125 or below), R81.20 (Take 165 or below)
Advisories Check Point sk1000117 / sk1000118; Canadian Centre for Cyber Security advisory
Exploited No indication of exploitation as at 2026-09-10

Asked in Check Point's own community thread whether gateways with the VPN software blade disabled remain affected, a vendor staff member replied that the issue concerns certificate processing, so it could in theory be triggered in an environment without VPN enabled but with VPN certificates present. Customers on the R81.10 branch reported in the same thread that neither Live Patch nor a Jumbo Hotfix was available to them, leaving the advisory's vaguely worded VPN implied-rules mitigation as the only option. See also CVE-2026-85102 and CVE-2026-16232.