The Exploit Bulletin — Sunday, September 13, 2026: 2 issues require action
Sunday, September 13, 2026 — 2 issues require action. If you run none of the software below, you are done.
Affects: Quantum Security · Quantum Security Gateway
1. Heap overflow in VPN certificate ASN.1 decoding allows unauthenticated RCE on Check Point Quantum Security Gateway and Management (CVE-2026-85103)
PUBLIC EXPLOIT · NO ATTACKS CONFIRMED · REMOTE CODE EXECUTION · CRITICAL · CVSS 9.8
A public write-up containing a request-level proof of concept is now available and the Dutch NCSC issued an alert on 2026-09-12 saying it expects exploitation attempts soon; no attacks are confirmed, but a team that leaves an internet-facing gateway on an old Jumbo Hotfix take is exposed to full device compromise once attempts begin.
A heap-based buffer overflow in the ASN.1 decoder used for VPN certificates lets an unauthenticated remote attacker execute arbitrary code on Check Point Quantum Security Gateway and Quantum Security Management systems. The vulnerable code path is reached through the VPN negotiation that these devices expose to the internet by design.
Affected: Quantum Security Gateway R82.10 with Jumbo Hotfix Take 43 or below; Quantum Security Gateway R82 with Jumbo Hotfix Take 125 or below; Quantum Security Gateway R81.20 with Jumbo Hotfix Take 165 or below; Quantum Security Management R82.10 with Jumbo Hotfix Take 43 or below; Quantum Security Management R82 with Jumbo Hotfix Take 125 or below; Quantum Security Management R81.20 with Jumbo Hotfix Take 165 or below
How to Test: On every gateway and management server, record the major release (R81.20, R82, R82.10) and the installed Jumbo Hotfix Accumulator Take; any R82.10 system at Take 43 or below, R82 at Take 125 or below, or R81.20 at Take 165 or below is affected. Because no in-the-wild indicators are published yet, review VPN daemon and connection logs for malformed or unexpected certificate exchanges and negotiation attempts from unknown source addresses, and look for unexpected processes or configuration changes on gateways that have been reachable since 2026-09-09.
How to Patch: Install the Jumbo Hotfix Accumulator referenced in Check Point advisory sk1000118: a take above 43 for R82.10, above 125 for R82, and above 165 for R81.20, on both Quantum Security Gateway and Quantum Security Management systems. If a gateway cannot be updated immediately, restrict which source addresses can reach its VPN endpoints until the hotfix is applied.
Evidence: BleepingComputer write-up with request-level PoC
2. Improper certificate trust validation in VPN negotiation allows unauthenticated RCE on Check Point Quantum Security Gateway (CVE-2026-85102)
PUBLIC EXPLOIT · NO ATTACKS CONFIRMED · REMOTE CODE EXECUTION · CRITICAL · CVSS 9.8
A public write-up with a request-level proof of concept is available and the Dutch NCSC warned on 2026-09-12 that it expects exploitation attempts soon; no attacks are confirmed, but an internet-facing gateway left on an old Jumbo Hotfix take can be fully compromised without credentials once attempts start.
Check Point Quantum Security Gateway fails to properly validate certificate trust during VPN negotiation, allowing an unauthenticated remote attacker to execute arbitrary code on the gateway. The flaw sits in the VPN service that these gateways expose to the internet.
Affected: Quantum Security Gateway R82.10 with Jumbo Hotfix Take 43 or below; Quantum Security Gateway R82 with Jumbo Hotfix Take 125 or below; Quantum Security Gateway R81.20 with Jumbo Hotfix Take 165 or below
How to Test: On every gateway, record the major release (R81.20, R82, R82.10) and the installed Jumbo Hotfix Accumulator Take; R82.10 at Take 43 or below, R82 at Take 125 or below, and R81.20 at Take 165 or below are affected. No in-the-wild indicators are published yet, so review VPN negotiation and daemon logs for certificate exchanges from untrusted or unexpected sources, and check gateways reachable since 2026-09-09 for unexpected processes, accounts, or configuration changes.
How to Patch: Install the Jumbo Hotfix Accumulator referenced in Check Point advisory sk1000117: a take above 43 for R82.10, above 125 for R82, and above 165 for R81.20. Until the hotfix is applied, limit which source addresses can reach the gateway's VPN endpoints.
Evidence: BleepingComputer write-up with request-level PoC
Read on the web · Every past edition
The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.
Spot an error, or an exploit we missed? Reply here or email [email protected].