Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A Critical Vulnerability in Check Point Security Management and Log Servers: A Threat to Enterprise Network Security


A critical vulnerability has been discovered in Check Point's Security Management and Log Servers, allowing unauthenticated attackers to run code as root on those servers over the network. This vulnerability has been rated 9.8 out of 10 on the CVSS scale and has significant implications for enterprise network security.

  • A critical vulnerability in Check Point's Security Management and Log Servers has been identified, allowing unauthenticated attackers to run code as root on those servers over the network.
  • The vulnerability, rated 9.8 out of 10 on the CVSS scale, is a stack overflow in the login process that can be triggered by a long username.
  • Check Point has released a fix through its LivePatch update channel and urges customers to apply it immediately.
  • The affected versions of Check Point's software include R82.10 and R81.10, among others.
  • To mitigate the vulnerability, customers should apply the LivePatch fix, limit management Trusted Clients access, and do not expose management access directly to the internet.
  • The vulnerability highlights the importance of keeping software up-to-date and patching vulnerabilities as soon as they are released.



  • A recent critical vulnerability in Check Point's Security Management and Log Servers has been identified, allowing unauthenticated attackers to run code as root on those servers over the network. This vulnerability, tracked as CVE-2026-91843, has been rated 9.8 out of 10 on the CVSS scale by Check Point, indicating a high level of severity and potential impact.

    The vulnerability, which was discovered by Check Point, is a stack overflow in the login process, which handles requests before a user is authenticated. Internet scanning company Censys said the overflow is triggered by a login request that carries a very long username. This means that even if an attacker does not have login credentials, they can still exploit the vulnerability to run malicious code as root on the affected servers.

    Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw has been exploited. However, the company has urged customers to apply the LivePatch fix immediately, as the vulnerability's severity and potential impact are significant.

    The affected versions of Check Point's software include R82.10 with Jumbo Hotfix Take 44 or below, R82 with Jumbo Hotfix Take 126 or below, R81.20 with Jumbo Hotfix Take 166 or below, and R81.10 with Jumbo Hotfix Take 190 or below. Standalone deployments, Log Servers, and Multi-Domain servers are also vulnerable, according to Aviv Abramovich, vice president of product management for network security at Check Point.

    To mitigate this vulnerability, Check Point recommends that customers apply the LivePatch fix to every Security Management Server and Log Server. If automatic updates are enabled, customers should confirm the fix has been installed rather than assume it. They should also check that management Trusted Clients access is limited to known, trusted hosts and not set to any IP address, and do not expose management access directly to the internet.

    The discovery of this vulnerability highlights the importance of keeping software up-to-date and patching vulnerabilities as soon as they are released. It also serves as a reminder that even small vulnerabilities can have significant consequences if exploited by attackers.

    In recent months, Check Point has disclosed several critical vulnerabilities in its software, including CVE-2026-16232, CVE-2026-62144, CVE-2026-18574, and CVE-2026-85103. These vulnerabilities have been rated high on the CVSS scale and have been exploited by attackers in the past.

    The recent vulnerability, CVE-2026-91843, is the fifth critical flaw since July 22 that an attacker could reach on the Security Management Server without logging in. The first, CVE-2026-16232, was exploited in July, and Check Point's Lotem Finkelstein wrote then that it affected "a handful of customers" in one configuration, "when Management is exposed directly to the internet without IP restrictions."

    CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog the same day, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) recorded exploitation as "none" in its assessment attached to the CVE record on September 17.

    The discovery of this vulnerability has also sparked concerns about the potential impact on enterprise network security. As the use of cloud-based services and remote work becomes more prevalent, the importance of securing network infrastructure has never been more critical.

    In conclusion, the recent critical vulnerability in Check Point's Security Management and Log Servers highlights the importance of keeping software up-to-date and patching vulnerabilities as soon as they are released. It also serves as a reminder that even small vulnerabilities can have significant consequences if exploited by attackers.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-Critical-Vulnerability-in-Check-Point-Security-Management-and-Log-Servers-A-Threat-to-Enterprise-Network-Security-ehn.shtml

  • https://thehackernews.com/2026/09/critical-check-point-management-server.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-91843

  • https://www.cvedetails.com/cve/CVE-2026-91843/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-16232

  • https://www.cvedetails.com/cve/CVE-2026-16232/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-62144

  • https://www.cvedetails.com/cve/CVE-2026-62144/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-18574

  • https://www.cvedetails.com/cve/CVE-2026-18574/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-85103

  • https://www.cvedetails.com/cve/CVE-2026-85103/


  • Published: Fri Sep 18 00:04:06 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us