CVE-2026-85103
Published Sep 9, 2026
Last updated a day ago
AI description
CVE-2026-85103 is identified as a heap-based buffer overflow vulnerability found within the VPN certificate ASN.1 decoding process. This flaw may enable an unauthenticated remote attacker to execute arbitrary code on affected systems. Specifically, it impacts Check Point Quantum Security Management and Quantum Security Gateway systems, as well as Check Point Spark Firewalls. The vulnerability affects several Check Point versions, including R81.20, R82, R82.10, and older end-of-support versions ranging from R80 to R81.10. Check Point has addressed this issue by releasing fixes through its automated LivePatch service and via Jumbo Hotfix Accumulator packages for the relevant product versions.
- Description
- A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
- Source
- cve@checkpoint.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- cve@checkpoint.com
- CWE-122
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
30
Check Point patched two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that could enable unauthenticated RCE on Security Gateway and Management systems under specific conditions. #CheckPoint #VPNFlaws #RCE https://t.co/EaRdt7iBxm
@TweetThreatNews
11 Sept 2026
211 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Two Check Point Quantum VPN bugs CVE-2026-85102 and CVE-2026-85103 allow unauthenticated code execution by sending attacker-controlled certificates during VPN negotiation. https://t.co/X8SPvXCcCV https://t.co/f6lH8cYbvY
@threatcluster
10 Sept 2026
60 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Check Point patched two critical 9.8-rated VPN certificate handling flaws (CVE-2026-85102, CVE-2026-85103) enabling unauthenticated RCE. Patch VPN gateways now. #CyberSecurity #CheckPoint #VPN https://t.co/PKW4PDH6BL
@CyberWorldOps
10 Sept 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
TRC analysis shows attackers exploiting VPN certificate validation flaws (CVE-2026-85102, CVE-2026-85103) to achieve unauthenticated RCE on Check Point Security Gateways. Compromised security infrastructure enables lateral movement across protected network segments. #ZeroTrust
@aviatrixtrc
10 Sept 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Check Point patched two CVSS 9.8 VPN cert issues (CVE-2026-85102, CVE-2026-85103)—unauth RCE under specific conditions. No known exploit yet. Apply Live Patch/Jumbo Hotfix on affected Quantum builds. https://t.co/unfsynufcM
@richtechguy
10 Sept 2026
69 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks Details: https://t.co/kq73xJ6NbD Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score o
@The_Cyber_News
10 Sept 2026
4832 Impressions
36 Retweets
92 Likes
17 Bookmarks
2 Replies
1 Quote
🚨🚨🚨 『CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions.』 [Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 https://t.co/YNDtCMPP86
@autumn_good_35
10 Sept 2026
404 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
@CheckPointSW disclosed two critical unauthenticated RCE flaws in Quantum Security Gateway VPN components. CVE-2026-85102 allows authentication bypass via weak certificate validation in Remote Access and Site-to-Site VPN. CVE-2026-85103 is a heap buffer overflow in ASN.1
@WorldCyberNewsX
10 Sept 2026
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
‼️ Check Point patched two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that could allow unauthenticated RCE under specific, undisclosed conditions. Both carry CVSS 9.8 scores. What’s affected and how to fix it: https://t.co/nPjElpoGTs
@TheHackersNews
10 Sept 2026
32533 Impressions
49 Retweets
166 Likes
52 Bookmarks
4 Replies
0 Quotes
Check Point fixed critical Check Point VPN vulnerabilities. Update gateways to prevent remote code execution under CVE-2026-85102 and CVE-2026-85103. #CheckPoint #VPN #Cybersecurity #CVE202685102 #CVE202685103 https://t.co/eWjnFLvoAP https://t.co/LObKeDeO3g
@Daily_CyberSec
9 Sept 2026
310 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes