CVE-2026-85103
Quantum Security Gateway and Management heap-based buffer overflow in VPN certificate ASN.1 decoding (CVE-2026-85103)
Check Point Quantum Security Gateway and Security Management are affected by a critical heap-based buffer overflow in VPN certificate ASN.1 decoding. An unauthenticated remote attacker could execute code. No fixed release is listed yet; restrict network exposure and monitor the vendor advisory.
What happened
A heap-based buffer overflow exists in the VPN certificate ASN.1 decoding of Check Point Quantum Security Gateway and Quantum Security Management. The vulnerability is reachable over the network without authentication and requires no user interaction, and Check Point states that an unauthenticated remote attacker may be able to execute arbitrary code. The CVSS 3.1 score is 9.8, reflecting low attack complexity and high impact on confidentiality, integrity and availability.
The data for this advisory records no exploitation and no public disclosure; CISA KEV does not list the CVE. No fixed release is listed yet in the vendor advisory.
Who is affected
The following products and versions are affected:
- Quantum Security Gateway: R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, R81.20 with Jumbo Hotfix Take 165 or below.
- Quantum Security Management: R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, R81.20 with Jumbo Hotfix Take 165 or below.
Quantum Security Gateway is a perimeter security gateway, and Quantum Security Management is the management platform. Because the attack vector is network-based, installations where these interfaces are reachable from untrusted networks are the most exposed.
What to do now
- Confirm whether your deployment runs an affected release: Quantum Security Gateway or Quantum Security Management at R82.10 with Jumbo Hotfix Take 43 or below, R82 with Jumbo Hotfix Take 125 or below, or R81.20 with Jumbo Hotfix Take 165 or below.
- Treat the affected systems as currently without a vendor fix: Check Point has not listed fixed versions or a workaround in SK1000118.
- Restrict network access to the affected management and VPN certificate processing interfaces, especially from the internet and untrusted networks.
- Monitor Check Point SK1000118 for any change in fix status.
- If exposure cannot be restricted now, raise the risk and prepare an emergency change so a future fixed release can be deployed promptly.
How to detect it
Check Point's advisory does not provide indicators of compromise. Because the attack vector is network-based and requires no credentials or user interaction, begin with exposure: identify any Quantum Security Gateway or Security Management interfaces reachable from untrusted networks, and verify whether affected Jumbo Hotfix take levels are present.
Beyond the patch
With no fixed release available, this is primarily an exposure problem today. Virtual CISO Services (vCISO) can help you identify network-reachable Check Point interfaces before an attacker does, and Managed Detection & Response (MDR) can monitor for the code execution and post-exploitation activity that may follow. Check Point has not published fixed versions yet, so containment and visibility are the controls that matter right now.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Quantum Security Gateway | R82.10 with Jumbo Hotfix Take 43 or below R82 with Jumbo Hotfix Take 125 or below R81.20 with Jumbo Hotfix Take 165 or below | No fixed version listed yet |
| Quantum Security Management | R82.10 with Jumbo Hotfix Take 43 or below R82 with Jumbo Hotfix Take 125 or below R81.20 with Jumbo Hotfix Take 165 or below | No fixed version listed yet |