Check PointCVE-2026-85103
Check Point Quantum Security: heap buffer overflow
Critical9.8CVE-2026-85103 · Published Sep 9, 2026 · updated Sep 10, 2026
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Quantum Security Gateway Product | <= R82.10 with Jumbo Hotfix Take 43 or below | No fix yet |
| <= R82 with Jumbo Hotfix Take 125 or below | No fix yet | |
| <= R81.20 with Jumbo Hotfix Take 165 or below | No fix yet | |
| Quantum Security Management Product | <= R82.10 with Jumbo Hotfix Take 43 or below | No fix yet |
| <= R82 with Jumbo Hotfix Take 125 or below | No fix yet | |
| <= R81.20 with Jumbo Hotfix Take 165 or below | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-122
More Check Point advisories
All Check Point| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 22 | Check Point Quantum Security Management: path traversal | Critical9.8 | No fix yet |
| Sep 16 | Check Point Quantum Security Management: stack buffer overflow | Critical9.8 | No fix yet |
| Sep 9 | Check Point Quantum Security Gateway: remote code execution | Critical9.8 | No fix yet |
| Aug 3 | Check Point Multi-Domain Security Management Server: authentication bypass | Critical9.3 | No fix yet |
| Jul 22 | Check Point Security Management: authentication bypass | Critical9.1 | No fix yet |
| Jul 22 | Check Point Gaia Portal: code execution | High7.5 | No fix yet |