Check Point CVE-2026-85102 CVE-2026-85103 are two critical VPN-related vulnerabilities that can allow unauthenticated remote code execution on affected Check Point systems. Both carry a CVSS score of 9.8, and Check Point has released remediation through supported Jumbo Hotfix and Live Patch channels.
The two flaws belong in one administrator patch decision rather than two separate remediation campaigns, but their affected-product scope is not identical. CVE-2026-85102 is focused on Quantum Security Gateway systems, while CVE-2026-85103 also affects Quantum Security Management systems in the vendor’s published vulnerability scope.
Check Point currently says it has no indication that either vulnerability is being actively exploited. That status can change, so administrators should treat exploitation state separately from severity and patch availability.
What are CVE-2026-85102 and CVE-2026-85103?
CVE-2026-85102 is an improper certificate trust-validation vulnerability during VPN negotiation. Under affected conditions, an unauthenticated remote attacker may be able to execute arbitrary code on a vulnerable Quantum Security Gateway.
CVE-2026-85103 is a heap-based buffer overflow associated with ASN.1 decoding of VPN certificate data. It can also lead to unauthenticated remote code execution, and its published product scope includes both Quantum Security Gateway and Quantum Security Management systems.
Which flaw affects Security Management?
CVE-2026-85103 is the important differentiator for administrators running Check Point management infrastructure. The published vulnerability record includes Quantum Security Management as well as Quantum Security Gateway, whereas CVE-2026-85102 is listed against the gateway product scope.
This does not mean every Check Point management deployment is automatically exploitable. Administrators still need to compare the installed release, hotfix level and relevant configuration with the current vendor advisory.
Which Check Point versions need attention?
For the supported release families reviewed by TPS, the vulnerable ranges extend through R81.20 Jumbo Hotfix Take 165, R82 through Take 125 and R82.10 through Take 43 for the relevant affected products. The corresponding fixed states begin with R81.20 Take 166, R82 Take 126 and R82.10 Take 44.
Administrators should not use those take numbers as a substitute for checking the vendor advisory for their exact appliance or management deployment. Older and end-of-support releases may require migration rather than a normal current-branch hotfix.
What fixes CVE-2026-85102 and CVE-2026-85103?
Check Point has published fixed Jumbo Hotfix releases for supported branches and began a Live Patch rollout on September 9, 2026. A system that is configured for automatic Live Patch delivery may receive protection without a full Jumbo Hotfix installation, but administrators should verify that the relevant protection is actually installed instead of assuming rollout succeeded.
For supported mainstream branches, the reviewed fixed states include R81.20 Take 166, R82 Take 126 and R82.10 Take 44. Current CERT guidance also identifies fixed Spark builds including R82.00.10 Build 2325 and R81.10.17 Build 4968.
Is active exploitation confirmed?
No active exploitation was indicated by Check Point in the vendor status reviewed by TPS. That is different from saying exploitation is impossible. These are remotely reachable critical vulnerabilities, so administrators should patch based on exposure and severity rather than wait for a confirmed exploitation campaign.
TPS did not identify evidence in the reviewed sources that either CVE had been added to CISA’s Known Exploited Vulnerabilities catalogue at the time of research.
Does Live Patch mean no further action is needed?
Not automatically. Live Patch can reduce the immediate exposure window when supported and successfully installed, but an administrator still needs to verify the system’s actual protection state. Check the appliance or management system for the relevant installed Live Patch or Jumbo Hotfix state and compare it with the current Check Point advisory.
If the deployment is already on a fixed Jumbo Hotfix take, the administrator should document that state as remediation evidence. If it is on an affected release and Live Patch has not installed, use the vendor-supported remediation path for that release.
What should end-of-support deployments do?
Current CERT guidance indicates that some end-of-support software does not receive a normal fix. Those deployments should be treated as an upgrade or migration problem rather than assuming an old branch will receive the same hotfix as a supported release.
Because security-gateway upgrades can affect routing, VPN, policy and availability, production change procedures should follow the organisation’s normal Check Point backup, validation and rollback controls.
What if the VPN blade is disabled?
The reviewed CERT and vendor material ties exposure to VPN-related processing, including Remote Access VPN or Site-to-Site VPN scenarios. However, configuration-specific discussion around CVE-2026-85103 leaves some edge cases unresolved. TPS therefore does not treat a disabled VPN blade alone as proof that every deployment is unaffected unless the current Check Point advisory confirms that conclusion for the exact product and configuration.
What administrators should verify now
Identify whether the system is a Quantum Security Gateway, Security Management deployment or Spark appliance. Record its exact release and installed Jumbo Hotfix take. Check whether the current Check Point advisory lists that product and version as affected. If it is affected, install or verify the supported fixed Jumbo Hotfix, Live Patch or Spark build and preserve the resulting patch-state evidence for the security record.
Both CVEs can be handled as one urgent patch campaign, but do not lose the product-scope distinction: CVE-2026-85103 is the one that additionally brings Check Point Security Management into the published affected scope.
What happens next?
The most important state changes to watch are a Check Point advisory revision, new affected-version guidance, confirmed exploitation, publication of indicators of compromise, or a change to the Live Patch and Jumbo Hotfix remediation paths. Those developments should update this same article while the administrator’s core reader job remains patch and exposure verification.
Verification note: TPS compared Check Point’s CVE-specific support advisories, vendor security communication and Jumbo Hotfix documentation with current CERT guidance. The vulnerabilities and supported fixes are confirmed. Active exploitation was not indicated by Check Point in the reviewed material, and some configuration-specific exposure questions remain unresolved.



