CVE-2026-85103: pre-auth remote code execution in Check Point Quantum Security Gateway

Remote attackers can crash or run code on Check Point Quantum Security Gateway and Quantum Security Management appliances by supplying malformed VPN certificate data that overflows a heap buffer (CVE-2026-85103). Affected releases include R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, and R81.20 with Jumbo Hotfix Take 165 or below across both Gateway and Management branches. Exploitation only requires network access to the vulnerable VPN/certificate handling service; no user authentication is needed.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.03652
CWE
CWE-122
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this flaw allows unauthenticated remote code execution against VPN/management interfaces, so immediately restrict exposure of those services to trusted networks.

What is CVE-2026-85103?

Remote attackers can crash or run code on Check Point Quantum Security Gateway and Quantum Security Management appliances by supplying malformed VPN certificate data that overflows a heap buffer (CVE-2026-85103). Affected releases include R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, and R81.20 with Jumbo Hotfix Take 165 or below across both Gateway and Management branches. Exploitation only requires network access to the vulnerable VPN/certificate handling service; no user authentication is needed. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Check Point Quantum Security Gateway are affected?

BRANCHAFFECTEDFIXED
Quantum Security GatewayR82.10 with Jumbo Hotfix Take 43 or below
Quantum Security GatewayR82 with Jumbo Hotfix Take 125 or below
Quantum Security GatewayR81.20 with Jumbo Hotfix Take 165 or below
Quantum Security ManagementR82.10 with Jumbo Hotfix Take 43 or below
Quantum Security ManagementR82 with Jumbo Hotfix Take 125 or below
Quantum Security ManagementR81.20 with Jumbo Hotfix Take 165 or below

Is CVE-2026-85103 being exploited?

There are no public reports of exploitation or public exploit code for this issue as of 2026-09-30.

How to fix CVE-2026-85103

  1. Block or restrict access to VPN and management interfaces from the internet and untrusted networks.
  2. Follow Check Point's published mitigations and configuration guidance until a vendor update is available.
  3. Enable and monitor detailed logs and intrusion detection alerts for certificate-processing and VPN traffic.
  4. Prepare to test and deploy vendor hotfixes or updates as soon as they are released.

Frequently asked questions

Is CVE-2026-85103 being actively exploited?

No public reports or exploit code were available as of 2026-09-30; CISA has not listed it in the Known Exploited Vulnerabilities catalog.

Which Quantum Security Gateway versions are affected by CVE-2026-85103?

Affected releases include R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, and R81.20 with Jumbo Hotfix Take 165 or below for both Quantum Security Gateway and Quantum Security Management branches.

Is there a patch for CVE-2026-85103?

As of 2026-09-30 there is no fixed release listed; follow Check Point guidance and apply vendor mitigations until a patch or hotfix is published.

Does CVE-2026-85103 require authentication?

No, the issue can be triggered by an unauthenticated remote attacker via the product's certificate processing.

References