CVE-2026-85103: Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Check Point Quantum Security Management and Quantum Security Gateway systems are identified as affected. The issue is in VPN certificate ASN.1 decoding, so exposure depends on whether the affected system processes attacker-supplied VPN certificates.
What access does an attacker need to exploit it?
The attack vector is network-based and requires no privileges or user interaction. An unauthenticated remote attacker may be able to exploit the flaw.
What could successful exploitation allow?
Successful exploitation may allow arbitrary code execution on the affected system. The reported impact includes high confidentiality, integrity, and availability impact.