Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
Check Point patched CVE-2026-91843 (CVSS 9.8), a pre-authentication stack overflow letting unauthenticated attackers run code as root on Security Management and Log Servers.
CVE-2026-91843 (CVSS 9.8) is a stack overflow in the pre-authentication login process of Check Point Security Management and Log Servers, reachable through the Trusted Clients setting. Check Point shipped a fix via LivePatch advisory sk1000155 and says there is no indication of exploitation; CISA also lists exploitation as none and no public PoC exists as of September 16. Affected branches span R80 through R82.20 (including end-of-support releases), and Censys observes 3,836 hosts presenting Check Point management identities. It is the fifth critical unauthenticated management flaw since July 22; the earlier SmartConsole bypass CVE-2026-16232 was exploited in July.
- Pre-auth stack overflow in login process, CVSS 9.8, reachable only via the Trusted Clients path
- Fixed through LivePatch advisory sk1000155; automatic-update customers already protected
- No exploitation observed, not in CISA KEV, and no public PoC as of September 16
- Affects R80-R82.20 branches including end-of-support versions; R82.20 lacks a Jumbo Hotfix
- Fifth critical unauthenticated management flaw since July 22, after exploited CVE-2026-16232
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-16232 | Authentication Bypass in Check Point SmartConsole Grants Full Admin Access Check Point SmartConsole, the administrative client used to manage Quantum Security Management and Multi-Domain Security Management, contains an authentication bypass (CWE-287) in its login process that allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. Exploitation is possible when the Management Server IP address is reachable from the internet and the configuration does not restrict Trusted Clients. A successful attacker can modify security policies and security configurations, effectively taking control of firewall management. Any organization running an internet-exposed Check Point management server without Trusted Client restrictions is affected, though Check Point reports exploitation has impacted only a very small number of customers. The flaw was added to CISA's KEV on 2026-07-22, is actively exploited, and press reports indicate public proof-of-concept code has been released. Do: Apply the fix released in Check Point's advisory for CVE-2026-16232 by updating SmartConsole and the associated Quantum/MDS management software; no fixed version numbers were provided in this data, so confirm them against the vendor bulletin. As an interim mitigation, restrict internet access to the Management Server IP address and configure Trusted Clients so SmartConsole connections are accepted only from known administrator addresses. Review management logs for unexpected logins, unauthenticated token issuance, or unfamiliar administrator sessions, and complete remediation per CISA BOD 26-04 given the KEV listing. | 9.3 | 72% | KEV |
| largeplausibly tens of thousands of Check Point management deployments, though the vulnerable subset is only those with an internet-exposed Management Server and no… | |
| CVE-2026-91843 | Unauthenticated stack overflow gives root RCE in Check Point login process CVE-2026-91843 is a stack-based buffer overflow (CWE-121) in the unauthenticated login process of a Check Point product, as Check Point Software ([email protected]) is the assigning CNA and its CVE scope covers Check Point products. An attacker can trigger the flaw remotely by sending crafted input to the login interface before authenticating, with no user interaction or credentials required. Successful exploitation allows arbitrary code execution with root privileges, the highest level of control on the affected system. The vulnerability is rated 9.8 Critical (AV:N/AC:L/PR:N/UI:N, all impacts high), reflecting trivial network exploitability. No public proof-of-concept or confirmed in-the-wild exploitation is known at this time, and the source data does not name the specific product line or affected version ranges. Do: Monitor Check Point's official advisory channels for the affected product/version list and patch release, and upgrade as soon as fixed versions are published. In the interim, restrict the login/management interface of Check Point appliances to trusted management networks and remove any direct internet exposure, and review perimeter logs for anomalous pre-authentication traffic against that interface. | 9.8 | — |
| — |
Full article1,123 words · extracted from thehackernews.com · click to collapse
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network.
The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw has been exploited.
Check Point told The Hacker News that the vulnerable path runs only through the Trusted Clients setting, which controls which hosts may connect to the management server through SmartConsole.
The flaw, tracked as CVE-2026-91843 and rated 9.8 out of 10 on the CVSS scale by Check Point, is a stack overflow in the login process, which handles requests before a user is authenticated. Internet scanning company Censys said the overflow is triggered by a login request that carries a very long username.
Check Point said in a notice on its CheckMates community on September 16, 2026, that customers with automatic updates enabled are already protected, and that everyone else should apply the LivePatch fix described in advisory sk1000155. It urged customers to take immediate action because of the flaw's severity and potential impact.
"At this time, there is no indication that this vulnerability has been exploited in the wild," the notice said. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recorded exploitation as "none" in its assessment attached to the CVE record on September 17.
The flaw was not in CISA's Known Exploited Vulnerabilities catalog as of the catalog's September 16 release, which The Hacker News checked on September 17. Censys said no public proof-of-concept exploit existed as of September 16. Aviv Abramovich, vice president of product management for network security at Check Point, told The Hacker News that the company had not received any reports of exploitation.
Affected Versions
Check Point's CVE record lists the following branches as affected, by Jumbo Hotfix Take, the numbered level of the update package that collects the fixes for a release.
A server on a listed branch at the listed Take or an older one is affected.
- R82.10 with Jumbo Hotfix Take 44 or below
- R82 with Jumbo Hotfix Take 126 or below
- R81.20 with Jumbo Hotfix Take 166 or below
- R81.10 with Jumbo Hotfix Take 190 or below, and R81, R80.40, R80.30, R80.20, R80.10 and R80, all of which are end of support
The record does not list R82.20, but Abramovich said R82.20 is also vulnerable. Censys said in its advisory that every R82.20 build is affected and that no Jumbo Hotfix yet protects that branch.
Standalone deployments, which run management and gateway on one system, Log Servers and Multi-Domain servers are also vulnerable, Abramovich said. An alert from NHS England Digital, citing sk1000155, says the hosted Smart-1 Cloud service is not affected because the fix is already in place there.
The CVE record marks R81.10 and the older branches as end-of-support. Check Point has a fix ready for those out-of-support versions, Abramovich said, and customers who need it should log a ticket with Check Point support.
What Administrators Should Do
- Apply the LivePatch fix described in sk1000155 to every Security Management Server and Log Server.
- If automatic updates are enabled, confirm the fix has been installed rather than assume it. The cplp list command shows which LivePatches are installed and their status.
- Whether or not the fix is installed, check that management Trusted Clients access is limited to known, trusted hosts and is not set to any IP address, and do not expose management access directly to the internet.
"Automatic updates" means the setting described in sk175504, according to Check Point's hardening guide. It is the checkbox in SmartConsole, under Global Properties and Data Access Control, labeled "Automatically download and install Software Blade Contracts, security updates, and other important data (highly recommended)," followed by the installation of the Access Control policy. LivePatch is the channel Check Point uses to push urgent security fixes to systems where that option is turned on.
Delivery is not always immediate. When Check Point pushed fixes for two VPN certificate flaws last week, several customers wrote in its community that the automatic package had not reached their systems on the day of the announcement, and a Check Point community admin replied that it was presumably being rolled out in stages rather than to everyone at once. Customers also found that the download links in those advisories appeared only after signing in to the User Center.
The Trusted Clients setting is in SmartConsole under Manage & Settings, Permissions & Administrators, Trusted Clients, according to the hardening guide, which also says that direct internet access to management should be avoided and that a VPN is required. The vulnerable path is "only through trusted clients," Abramovich said, and Check Point recommends that customers verify the setting is not set to any IP address but to trusted hosts.
Censys said it observes 3,836 hosts worldwide that present the default identity Check Point gives its management and log servers, a method it chose because build and hotfix level are not visible in scan data. "This figure is total role presence, not a confirmed-vulnerable count," the company said.
Fifth Critical Management Flaw Since July
By The Hacker News' count of Check Point's CVE records, CVE-2026-91843 is the fifth critical flaw since July 22 that an attacker could reach on the Security Management Server without logging in.
The first, CVE-2026-16232, a SmartConsole authentication bypass, was exploited in July. Check Point's Lotem Finkelstein wrote then that it affected "a handful of customers" in one configuration, "when Management is exposed directly to the internet without IP restrictions." The first mitigation step then was the one recommended now: limit Trusted Clients to trusted addresses.
CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog the same day. A second management bypass disclosed that day, CVE-2026-62144, was not reported as exploited.
Two more followed: CVE-2026-18574, an authentication bypass that could allow command execution on the management server, on August 3, and CVE-2026-85103, a heap overflow in VPN certificate decoding that also reaches Quantum Security Management, on September 9. Check Point said it found both internally and had no indication of exploitation.
Who found CVE-2026-91843 has not been disclosed, and Check Point did not address that question in its response.
Update: This article was updated on September 18, 2026, with responses from Check Point confirming that R82.20, standalone deployments, Log Servers and Multi-Domain servers are vulnerable, that the vulnerable path runs only through the Trusted Clients setting, and that a fix for out-of-support versions is available through Check Point support.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/critical-check-point-management-server.html