important · Edge — Check Point
Unauthenticated VPN negotiation can execute code on affected Check Point gateways and management servers.
Affects
Check Point Security Gateway, Spark appliances and, for CVE-2026-85103, Security Management Server installations processing VPN certificates.
Malformed certificate data can reach either improper validation or an ASN.1-decoding heap overflow in deployments using Remote Access or Site-to-Site VPN.
Detail and 4 sources
Check Point has published fixes; no public exploit or independent reproduction was established.