Critical [CVE-2026-85103] Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding
This critical-severity Check Point advisory covers CVE-2026-85103 affecting Quantum Security Gateway, Quantum Security Management, Security Management Server.
Android app · Google Play
Monitor future Check Point CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
Affected products named by the advisory: Security Management Server; Spark Firewall (Locally Managed); Spark Firewall (Centrally Managed).
- Quantum Security Gateway R82.10 with Jumbo Hotfix Take 43 or below
- Quantum Security Gateway R82 with Jumbo Hotfix Take 125 or below
- Quantum Security Gateway R81.20 with Jumbo Hotfix Take 165 or below
- Quantum Security Management R82.10 with Jumbo Hotfix Take 43 or below
- Quantum Security Management R82 with Jumbo Hotfix Take 125 or below
- Quantum Security Management R81.20 with Jumbo Hotfix Take 165 or below
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
- R82.10 Jumbo Hotfix Accumulator Take 44 or later
- R82 Jumbo Hotfix Accumulator Take 126 or later
- R81.20 Jumbo Hotfix Accumulator Take 166 or later
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Mitigation checklist
- This problem was fixed. Option 1: If you have enabled automatic installation of Check Point LivePatch, you are already protected. Version Take Number Download Package R82.10 BUNDLE_URGENT_SECURITY_UPDATE_R82_10_AUTOUPDATE take 24 (TAR) R82 BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE take 24 (TAR) R81.20 BUNDLE_URGENT_SECURITY_UPDATE_R81_20_AUTOUPDATE take 24 (TAR) To validate that LivePatch is properly installed and active, run the cpinfo -y CPupdates command on the Security Gateway / ClusterXL member in Expert mode and validate that you have BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE Take 24 Example: [Expert@Host:0]# cpinfo -y CPupdates [CPUpdates] BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE Take: 24 For LivePatch validation, run in Expert mode: On a Security Gateway / ClusterXL member: cplp list On a Scalable Platform Security Group: g_all cplp list Expected output: cpcert:cpca* CVE-2026-85102 CVE-2026-85103 cpcert:iked* CVE-2026-85102 CVE-2026-85103 cpcert:vpn* CVE-2026-85102 CVE-2026-85103 cpcert:vpnrad* CVE-2026-85102 CVE-2026-85103 cpcert_cprid:cprid* CVE-2026-85102 CVE-2026-85103 Option 2: The fix is also included in: Jumbo Hotfix Accumulator for R82.10 starting from Take 44 Jumbo Hotfix Accumulator for R82 starting from Take 126 Jumbo Hotfix Accumulator for R81.20 starting from Take 166 Check Point Spark Firewalls R82.00.10 starting from Build 2325 Check Point Spark Firewalls R81.10.17 starting from Build 4968
Official advisory · high-confidence parse· fetched 2 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.