Check Point has disclosed and patched two critical vulnerabilities affecting its VPN certificate processing mechanisms. Both vulnerabilities are rated CVSS 9.8 (Critical) and may enable an unauthenticated remote attacker to achieve Remote Code Execution (RCE) under specific, undisclosed conditions. Check Point has stated that it has not observed active exploitation of either vulnerability at the time of disclosure
CVE-2026-85102
Type: Improper Certificate Trust Validation
This vulnerability stems from a failure to properly validate certificate trust during VPN negotiation. Successful exploitation could allow an unauthenticated attacker to execute arbitrary code on affected Security Gateway devices.
CVE-2026-85103
Type:Heap-Based Buffer Overflow
This vulnerability occurs during the decoding of ASN.1 certificate structures used in VPN certificate processing. Successful exploitation could allow unauthenticated remote code execution against both Quantum Security Gateway and Quantum Security Management Server systems.
Check Point identifies the following versions as affected:
These versions are listed as vulnerable and require remediation
Immediate
Short-Term
If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively get in touch to find out how you can protect your organisation.