Vulnerability Intelligence Report
Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding
CVE-2026-85103
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-122 ↗CWE-122: Heap-based Buffer Overflow.
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| checkpoint | Quantum Security Gateway | R82.10 with Jumbo Hotfix Take 43 or below (affected), R82 with Jumbo Hotfix Take 125 or below (affected), R81.20 with Jumbo Hotfix Take 165 or below (affected) |
| checkpoint | Quantum Security Management | R82.10 with Jumbo Hotfix Take 43 or below (affected), R82 with Jumbo Hotfix Take 125 or below (affected), R81.20 with Jumbo Hotfix Take 165 or below (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Check Point Software Ltd. · Vendor · Israel |
| Reserved | 2026-09-03T06:38:15 |
| Published | 2026-09-09T13:00:42 |
| Last Updated | 2026-09-10T03:56:41 |
Community Chatter & Buzz