ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security
Part of a story covered by 10 sources: “Dutch NCSC warns of imminent exploitation of critical Check Point VPN RCE flaws; vendor also patches pre-auth root RCE in management servers” — merged summary and timeline →

Check Point security advisory (AV26-933)

mediumAdvisoryimportance 32CVE-2026-91843
AI summary · glm-5.3-flash

Canadian Cyber Centre relays Check Point advisory for CVE-2026-91843, a stack overflow in the login process of Security Management and Log Servers.

On September 17, 2026, the Canadian Centre for Cyber Security (AV26-933) published an advisory for a Check Point vulnerability tracked as CVE-2026-91843. The flaw is a stack overflow in the login process affecting Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server versions R81.20 (Jumbo Hotfix Take 166 and prior), R82 (Take 126 and prior), R82.10 (Take 44 and prior) and R82.20. Administrators are urged to review Check Point sk1000155 and apply updates as they become available.

  • CVE-2026-91843 is a stack overflow in Check Point management and log server login processes.
  • Affected versions include R81.20 Take 166 and prior, R82 Take 126 and prior, R82.10 Take 44 and prior, and R82.20.
  • Advisory AV26-933 references Check Point sk1000155; updates should be applied as available.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-91843
Unauthenticated stack overflow gives root RCE in Check Point login process

CVE-2026-91843 is a stack-based buffer overflow (CWE-121) in the unauthenticated login process of a Check Point product, as Check Point Software ([email protected]) is the assigning CNA and its CVE scope covers Check Point products. An attacker can trigger the flaw remotely by sending crafted input to the login interface before authenticating, with no user interaction or credentials required. Successful exploitation allows arbitrary code execution with root privileges, the highest level of control on the affected system. The vulnerability is rated 9.8 Critical (AV:N/AC:L/PR:N/UI:N, all impacts high), reflecting trivial network exploitability. No public proof-of-concept or confirmed in-the-wild exploitation is known at this time, and the source data does not name the specific product line or affected version ranges.

Do: Monitor Check Point's official advisory channels for the affected product/version list and patch release, and upgrade as soon as fixed versions are published. In the interim, restrict the login/management interface of Check Point appliances to trusted management networks and remove any direct internet exposure, and review perimeter logs for anomalous pre-authentication traffic against that interface.

9.8
  • Check Point
Full article105 words · extracted from cyber.gc.ca · click to collapse

Serial number: AV26-933
Date: September 17, 2026

As of September 16, 2026, Check Point is affected by a vulnerability in the following products:

  • Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server
    • R81.20 with Jumbo Hotfix Take 166 and prior
    • R82 with Jumbo Hotfix Take 126 and prior
    • R82.10 with Jumbo Hotfix Take 44 and prior
    • R82.20

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-933