CVE-2026-85103

Published Sep 9, 2026

Last updated a day ago

CVSS critical 9.8
Check Point Quantum Security Management
Quantum Security Gateway

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-85103 is identified as a heap-based buffer overflow vulnerability found within the VPN certificate ASN.1 decoding process. This flaw may enable an unauthenticated remote attacker to execute arbitrary code on affected systems. Specifically, it impacts Check Point Quantum Security Management and Quantum Security Gateway systems, as well as Check Point Spark Firewalls. The vulnerability affects several Check Point versions, including R81.20, R82, R82.10, and older end-of-support versions ranging from R80 to R81.10. Check Point has addressed this issue by releasing fixes through its automated LivePatch service and via Jumbo Hotfix Accumulator packages for the relevant product versions.

Description
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
Source
cve@checkpoint.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cve@checkpoint.com
CWE-122

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

30

  1. Check Point patched two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that could enable unauthenticated RCE on Security Gateway and Management systems under specific conditions. #CheckPoint #VPNFlaws #RCE https://t.co/EaRdt7iBxm

    @TweetThreatNews

    11 Sept 2026

    211 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Two Check Point Quantum VPN bugs CVE-2026-85102 and CVE-2026-85103 allow unauthenticated code execution by sending attacker-controlled certificates during VPN negotiation. https://t.co/X8SPvXCcCV https://t.co/f6lH8cYbvY

    @threatcluster

    10 Sept 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Check Point patched two critical 9.8-rated VPN certificate handling flaws (CVE-2026-85102, CVE-2026-85103) enabling unauthenticated RCE. Patch VPN gateways now. #CyberSecurity #CheckPoint #VPN https://t.co/PKW4PDH6BL

    @CyberWorldOps

    10 Sept 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. TRC analysis shows attackers exploiting VPN certificate validation flaws (CVE-2026-85102, CVE-2026-85103) to achieve unauthenticated RCE on Check Point Security Gateways. Compromised security infrastructure enables lateral movement across protected network segments. #ZeroTrust

    @aviatrixtrc

    10 Sept 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Check Point patched two CVSS 9.8 VPN cert issues (CVE-2026-85102, CVE-2026-85103)—unauth RCE under specific conditions. No known exploit yet. Apply Live Patch/Jumbo Hotfix on affected Quantum builds. https://t.co/unfsynufcM

    @richtechguy

    10 Sept 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ⚠️ Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks Details: https://t.co/kq73xJ6NbD Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score o

    @The_Cyber_News

    10 Sept 2026

    4832 Impressions

    36 Retweets

    92 Likes

    17 Bookmarks

    2 Replies

    1 Quote

  7. 🚨🚨🚨 『CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions.』 [Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510 https://t.co/YNDtCMPP86

    @autumn_good_35

    10 Sept 2026

    404 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. @CheckPointSW disclosed two critical unauthenticated RCE flaws in Quantum Security Gateway VPN components. CVE-2026-85102 allows authentication bypass via weak certificate validation in Remote Access and Site-to-Site VPN. CVE-2026-85103 is a heap buffer overflow in ASN.1

    @WorldCyberNewsX

    10 Sept 2026

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. ‼️ Check Point patched two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that could allow unauthenticated RCE under specific, undisclosed conditions. Both carry CVSS 9.8 scores. What’s affected and how to fix it: https://t.co/nPjElpoGTs

    @TheHackersNews

    10 Sept 2026

    32533 Impressions

    49 Retweets

    166 Likes

    52 Bookmarks

    4 Replies

    0 Quotes

  10. Check Point fixed critical Check Point VPN vulnerabilities. Update gateways to prevent remote code execution under CVE-2026-85102 and CVE-2026-85103. #CheckPoint #VPN #Cybersecurity #CVE202685102 #CVE202685103 https://t.co/eWjnFLvoAP https://t.co/LObKeDeO3g

    @Daily_CyberSec

    9 Sept 2026

    310 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.