> Source: [sk1000118](https://support.checkpoint.com/results/sk/sk1000118)

# sk1000118 - CVE-2026-85103 - ASN.1 decoding heap overflow leading to a remote code execution

| Property | Value |
|----------|-------|
| Solution ID | sk1000118 |
| Date Created | 2026-09-07 |
| Last Modified | 2026-09-18 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Spark Firewall (Locally Managed), Spark Firewall (Centrally Managed) |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.10, R82, R81.20, R82.00.X, R81.10.X, R81 (EOS), R81.10 (EOS), R81 (EOS), R81.10.X, R82.00.X |

## Symptoms

- <br />

* **Issue:** A heap overflow in the VPN certificate ASN.1 decoding flow may allow an attacker to remotely execute arbitrary code on the Security Management Server and Security Gateway.  
  **Clarification:** All Security Management Server deployments are vulnerable, regardless of configuration, and require the fix described below. The vulnerability is not dependent on any specific management configuration. The management is vulnerable even when VPN in not in use or configured.
* This issue received the ID [CVE-2026-85103](https://www.cve.org/CVERecord?id=CVE-2026-85103) with CVSS: 9.8.
* **Affected Products:**Security Management Server, Security Gateway, Check Point Spark Firewall
* **Affected Versions:**
  * R81.20, R82, R82.10
  * R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10 (all EoS)
  * R81.10.x, R82.00.x
* **Not Affected Versions:**R82.20

### Mitigation

**Note** - Use this mitigation only if the affected system cannot be updated through Jumbo Hotfix Accumulator or LivePatch. Exercise caution when disabling VPN implied rules and configuring explicit rules, as an incorrect configuration can cause connectivity issues.

**For Site to Site VPN** , disable implied rules for VPN and manually define VPN access for UDP/500 and UDP/4500 for the specific peer IP addresses. Refer to [sk179346](https://support.checkpoint.com/results/sk/sk179346).  

**For Remote Access VPN**:

Disable the Remote Access VPN implied rules. Create explicit Access Control rules that allow the required Remote Access VPN services to the Security Gateway:

* UDP/500 (IKE), UDP/4500 (NAT-T), TCP/443 (SSL), TCP/80 (when applicable)
* Specify the source of the Remote Access clients IP address ranges if applicable.

**Note:** This mitigation option is not applicable to the locally managed Spark Firewall.

## Solution

This problem was fixed.

### Option 1: The fix is included in [Check Point LivePatch](https://support.checkpoint.com/results/sk/sk185114)

**Automatic installation**

If you have enabled automatic installation of Check Point LivePatch, **the protection will be applied automatically**.

**Manual installation**

Download the offline package from the table below:

|------------|-------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------|
| Version    | Take Number                                                 | Download Package                                                                                                         |
| **R82.10** | BUNDLE_URGENT_SECURITY_UPDATE_R82_10_AUTOUPDATE **take 24** | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/145415) (TAR) |
| **R82**    | BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE **take 24**    | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/145416) (TAR) |
| **R81.20** | BUNDLE_URGENT_SECURITY_UPDATE_R81_20_AUTOUPDATE **take 24** | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/145417) (TAR) |

For instructions on the offline package installation procedure, refer to [sk185114](https://support.checkpoint.com/results/sk/sk185114).

To validate that LivePatch is properly installed and active, run the cpinfo -y CPupdates command on the Security Gateway / ClusterXL member in Expert mode and validate that you have BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE Take 24

Example:

```
[Expert@Host:0]# cpinfo -y CPupdates
[CPUpdates]
??BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE??Take:� 24
```

For LivePatch validation, run in Expert mode:

* On a Security Gateway / ClusterXL member:cplp list
* On a Scalable Platform Security Group: g_all cplp list

Expected output:

```
cpcert:cpca*����������CVE-2026-85102 CVE-2026-85103
cpcert:iked*��������� CVE-2026-85102 CVE-2026-85103
cpcert:vpn*���������� CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad*������  CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid*�� CVE-2026-85102 CVE-2026-85103
```

### Option 2: The fix is also included in:

* **[Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 44**
* **[Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 126**
* **[Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 166**
* **[Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 190**
* **[Check Point Spark Firewalls R82.00.10](https://support.checkpoint.com/results/sk/sk184357) starting from Build 2325**
* **[Check Point Spark Firewalls R81.10.17](https://support.checkpoint.com/results/sk/sk183153) starting from Build 4968**

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
