Critical Vulnerabilities in Check Point Quantum Security Gateway and Security Management Server
14 September 2026
Attackers can exploit critical vulnerabilities in Check Point Quantum Security Gateway and Security Management Server to perform remote code execution without authentication. Patch immediately.
Background
Check Point has released security updates to address multiple vulnerabilities (CVE-2026-85102 and CVE-2026-85103) affecting Check Point Quantum Security Gateway, Security Management Server, and Spark Firewall. These vulnerabilities have a Common Vulnerability Scoring System (CVSS v3.1) score of 9.8 out of 10 each.
Impact
Successful exploitation of these vulnerabilities could lead to the following:
CVE-2026-85102: Due to improper validation of certificate data during VPN negotiation, an unauthenticated remote attacker could execute arbitrary code on the affected Security Gateway.
CVE-2026-85103: Due to a heap overflow vulnerability in the VPN certificate ASN.1 decoding process, an unauthenticated remote attacker could execute arbitrary code on the affected Security Gateway or Security Management Server.
Affected Products
These vulnerabilities affect the following products and versions:
CVE-2026-85102 (Security Gateway and Check Point Spark Firewall using Site-to-Site VPN or Remote Access VPN):
R81.20, R82, R82.10
R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10 (all End-of-Support)
R81.10.x, R82.00.x
CVE-2026-85103 (Security Management Server, Security Gateway, and Check Point Spark Firewall):
R81.20, R82, R82.10
R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10 (all End-of-Support)
R81.10.x, R82.00.x
Unaffected Versions: R82.20
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
Mitigation
For Site-to-Site VPN deployments that cannot be patched immediately, Check Point recommends disabling implied VPN rules and restricting VPN access for UDP ports 500 and 4500 to known peer IP addresses. Note that this mitigation option is not applicable to the locally managed Spark Firewall.
References
https://support.checkpoint.com/results/sk/sk1000117 (opens in new tab)
https://support.checkpoint.com/results/sk/sk1000118 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-85102 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-85103 (opens in new tab)
