ZeroHour
Organization

NHS England Digital

1 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

Check Point patched CVE-2026-91843 (CVSS 9.8), a pre-authentication stack overflow letting unauthenticated attackers run code as root on Security Management and Log Servers.

CVE-2026-91843 (CVSS 9.8) is a stack overflow in the pre-authentication login process of Check Point Security Management and Log Servers, reachable through the Trusted Clients setting. Check Point shipped a fix via LivePatch advisory sk1000155 and says there is no indication of exploitation; CISA also lists exploitation as none and no public PoC exists as of September 16. Affected branches span R80 through R82.20 (including end-of-support releases), and Censys observes 3,836 hosts presenting Check Point management identities. It is the fifth critical unauthenticated management flaw since July 22; the earlier SmartConsole bypass CVE-2026-16232 was exploited in July.

The Hacker Newsupdated · 4h agofirst · 20h agoVulnerability 10 sourcesCVE-2026-91843CVE-2026-16232

Related CVEs

  • Authentication Bypass in Check Point SmartConsole Grants Full Admin Access
    Check Point SmartConsole, the administrative client used to manage Quantum Security Management and Multi-Domain Security Management, contains an authentication bypass (CWE-287) in its login process that allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. Exploitation is possible when the Management Server IP address is reachable from the internet and the configuration does not restrict Trusted Clients. A successful attacker can modify security policies and security configurations, effectively taking control of firewall management. Any organization running an internet-exposed Check Point management server without Trusted Client restrictions is affected, though Check Point reports exploitation has impacted only a very small number of customers. The flaw was added to CISA's KEV on 2026-07-22, is actively exploited, and press reports indicate public proof-of-concept code has been released.
    · Check Point SmartConsole · Check Point Quantum Security Management KEVlarge
  • Unauthenticated stack overflow gives root RCE in Check Point login process
    CVE-2026-91843 is a stack-based buffer overflow (CWE-121) in the unauthenticated login process of a Check Point product, as Check Point Software ([email protected]) is the assigning CNA and its CVE scope covers Check Point products. An attacker can trigger the flaw remotely by sending crafted input to the login interface before authenticating, with no user interaction or credentials required. Successful exploitation allows arbitrary code execution with root privileges, the highest level of control on the affected system. The vulnerability is rated 9.8 Critical (AV:N/AC:L/PR:N/UI:N, all impacts high), reflecting trivial network exploitability. No public proof-of-concept or confirmed in-the-wild exploitation is known at this time, and the source data does not name the specific product line or affected version ranges.
    · Check Point

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.