CVE-2026-85103
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
- Published Sep 9, 2026
- CVSS 9.8 critical
- 3.7% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks The Hacker News ·
- Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root The Hacker News ·
- Critical Vulnerabilities in Check Point Products CERT-EU ·
- Check Point security advisory (AV26-902) – Update 2 Canadian Centre for Cyber Security ·