CVE-2026-85103: Check Point Quantum Security Gateway

Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.

A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.

Affected products

  • Check Point Quantum Security Gateway: up to and including R82.10; up to and including R81.20
  • Check Point Quantum Security Management: up to and including R82.10; up to and including R81.20

Published 2026-09-09. Last modified 2026-09-10.