ZeroHour
Security Affairspublished ()ingested Pierluigi Paganini
Part of a story covered by 10 sources: “Dutch NCSC warns of imminent exploitation of critical Check Point VPN RCE flaws; vendor also patches pre-auth root RCE in management servers” — merged summary and timeline →

Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution

AI summary · glm-5.3-flash

Check Point patched CVE-2026-91843 (CVSS 9.8), a pre-authentication root RCE in Security Management and Log Servers; no exploitation observed.

Check Point fixed CVE-2026-91843 (CVSS 9.8), an unauthenticated stack overflow in the Security Management and Log Server login process that enables remote code execution as root. The attack path requires the Trusted Clients setting governing SmartConsole access and affects versions from R80 through R82.20 below listed hotfix takes. The fix ships via LivePatch under advisory sk1000155; Censys observed 3,836 hosts with the management role and no public PoC as of September 16.

  • Stack overflow triggered by an extremely long username sent to the pre-authentication login process.
  • Attack path requires the Trusted Clients setting controlling SmartConsole access to the management server.
  • Affected versions span R80 through R82.20, including multiple end-of-support releases.
  • Fix delivered via LivePatch (advisory sk1000155); auto-update customers are already protected.
  • Censys counted 3,836 hosts with the management/log server role; no exploitation or PoC seen.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-91843
Unauthenticated stack overflow gives root RCE in Check Point login process

CVE-2026-91843 is a stack-based buffer overflow (CWE-121) in the unauthenticated login process of a Check Point product, as Check Point Software ([email protected]) is the assigning CNA and its CVE scope covers Check Point products. An attacker can trigger the flaw remotely by sending crafted input to the login interface before authenticating, with no user interaction or credentials required. Successful exploitation allows arbitrary code execution with root privileges, the highest level of control on the affected system. The vulnerability is rated 9.8 Critical (AV:N/AC:L/PR:N/UI:N, all impacts high), reflecting trivial network exploitability. No public proof-of-concept or confirmed in-the-wild exploitation is known at this time, and the source data does not name the specific product line or affected version ranges.

Do: Monitor Check Point's official advisory channels for the affected product/version list and patch release, and upgrade as soon as fixed versions are published. In the interim, restrict the login/management interface of Check Point appliances to trusted management networks and remove any direct internet exposure, and review perimeter logs for anomalous pre-authentication traffic against that interface.

9.8
  • Check Point
Full article436 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 18, 2026

Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed.

Check Point addressed CVE-2026-91843 (CVSS score of 9.8), a critical vulnerability in its Security Management and Log Servers. The flaw could let an attacker with no account run code as root over the network.

The flaw sits in the login process before authentication. Censys researchers found that an attacker can trigger the stack overflow by sending a login request with an extremely long username.

“This vulnerability may allow an unauthenticated attacker to remotely execute arbitrary code with root privileges through the login process.” reads the advisory. “At this time, there is no indication that this vulnerability has been exploited in the wild. However, due to its critical severity and potential impact, we strongly recommend taking immediate action to protect your environment.”

Check Point said the attack path works only when customers use the Trusted Clients setting, which controls access to the management server through SmartConsole.

Affected versions includes:

  • R82.20
  • R82.10 Jumbo Hotfix Take 44 or lower
  • R82 Jumbo Hotfix Take 126 or lower
  • R81.20 Jumbo Hotfix Take 166 or lower
  • R81.10 Jumbo Hotfix Take 190 or lower (EoS)
  • R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS)

Check Point released the fix through its LivePatch channel. Customers with automatic updates enabled should already have protection, while others need to apply the update described in advisory sk1000155. The company urged customers to act.

So far, Check Point is not aware of real-world exploitation of the flaw. Censys reported no public proof-of-concept exploit as of September 16.

Organizations should check their update status and apply the fix if required. These servers manage firewall and admin access, so teams should patch them quickly.

Organizations should apply the LivePatch fix described in sk1000155. Customers who have automatic updates enabled should already have the fix.

As an additional security measure, organizations should follow the recommendations in the Check Point Management and Gateway hardening best practices guide. They should also limit Trusted Clients access on the management server to specific, known internal IP addresses.

“Censys observes 3,836 hosts globally carrying the Security Management/Log Server role, identified by the Security Internal Communication (SIC) identity Check Point assigns management servers by default rather than by version, since build and Jumbo Hotfix level are not visible in passive scan data.” reads the advisory by Censys. “This figure is total role presence, not a confirmed-vulnerable count.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CVE-2026-91843)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/199279/security/check-point-fixes-critical-cve-2026-91843-allowing-root-code-execution.html