Check Point Flaw Rated 9.8 Lets Attackers Run Code as Root

Check Point filed a CVE record on September 16 for CVE-2026-91843, a flaw in its Quantum Security Management platform that the company scores 9.8 out of 10 on the CVSS scale. In the record it filed as the assigning authority, Check Point describes the bug in one line: "A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges." The Hacker News reported on September 17 that the overflow is set off by a login request carrying an excessively long username.
The flaw is classified as CWE-121, a stack-based buffer overflow. Its CVSS vector spells out why the score is so high: the attack comes over the network, is low in complexity, and needs neither privileges nor any action from a user. The management server is the console administrators use to run their firewall estate, so code execution there lands on the machine that holds the rules, not on a single gateway.
Check Point's own CVE filing lists R82.10 with Jumbo Hotfix Take 44 or below, R82 with Take 126 or below, R81.20 with Take 166 or below and R81.10 with Take 190 or below, alongside the end-of-support R81, R80.40, R80.30, R80.20, R80.10 and R80 lines. The Hacker News adds that R82.20 is affected in every build with no Jumbo Hotfix protection available yet, and that the hosted Smart-1 Cloud service is not affected.
Sources differ on how much a server's configuration narrows the exposure. BleepingComputer, citing Check Point, reported on September 18 that "all Security Management Server deployments are vulnerable, regardless of configuration" and that the flaw "is not dependent on any specific management configuration." Aviv Abramovich, Check Point's vice president of product management for network security, told The Hacker News that the vulnerable path runs only through the Trusted Clients setting, which governs which hosts may reach the management server from SmartConsole. In the guidance BleepingComputer reported, that same setting appears as a mitigation: restrict it to known addresses and subnets.
Check Point says it has no indication the flaw has been exploited. CISA's Vulnrichment assessment, timestamped September 17, also records exploitation as "none" — while marking the flaw automatable with a technical impact of "total." SecurityWeek reported on September 18 that Check Point shared indicators of compromise and pressed customers without automatic updates to move quickly. The fix reaches servers through the LivePatch channel and is documented in advisory sk1000155, installing on its own where automatic updates are enabled.
Two things remain open. Neither Check Point nor the CVE record names who found the bug or when it was reported. And the counting of this year's Check Point flaws is not settled: The Hacker News calls it the fifth critical unauthenticated management-plane flaw since July 2026, listing CVE-2026-16232, CVE-2026-62144, CVE-2026-18574 and CVE-2026-85103, while BleepingComputer's own roundup of recent Check Point issues names a partly different set.
Sources
- CVE Program — CVE-2026-91843 record (Check Point as CNA)Primary source
- NVD — CVE-2026-91843Primary source
- Check Point advisory sk1000155Primary source
- The Hacker NewsSecondary
- BleepingComputerSecondary
- SecurityWeekSecondary
Related
WordPress 7.1.1 Patches Click2Shell: One Link Installs a Theme
BragJack: One Extension Hijacked AI Agents in 5 Browsers
Google Says Gemini Hacked Three Real Companies in May Test
Microsoft Discloses CVSS 10.0 Azure AI Foundry Flaw, Already Fixed
Docker Sandboxes Flaw Rated 9.4 Let Code Escape to Mac Host
Plugin4Shell: 4 AI Coding Agents Hit, 2 Still Unpatched
3 Linux Kernel Flaws Exploited; CISA Sets Sept. 21 Patch Deadline
Researchers Used Claude to Reach OpenAI Repos, Won $6,500
Trending now
- Google Says Gemini Hacked Three Real Companies in May Test
- Sharks Feed on Beached Whale in Jamaica; NEPA Warns Swimmers
- Claude Leads 26% of Anthropic's AI R&D, Up From 1% in March
- Microsoft Discloses CVSS 10.0 Azure AI Foundry Flaw, Already Fixed
- Anthropic Targets November IPO at About $2 Trillion Value
- Universal, Sony Sue Suno Again Over 60,202 Recordings
- China's CXMT Starts Mass Production of 11.95nm G5 DRAM
- NASA: Roman Telescope Has Fuel for 22 Years, Not 10
Comments
No comments yet. Be the first.