Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Check Point Fixes Critical CVE-2026-91843, a Critical Vulnerability Allowing Root Code Execution




Check Point has recently released a critical fix for the CVE-2026-91843 vulnerability, a serious flaw that could allow attackers to execute root code without needing a login. This vulnerability has a CVSS score of 9.8, making it a critical threat. Organizations should check their update status and apply the fix if required to protect their environment from this critical vulnerability.

  • Check Point has released a critical fix for the CVE-2026-91843 vulnerability, which allows attackers to execute root code without needing a login.
  • The affected versions of Check Point's Security Management and Log Servers include R82.20, R82.10, R81.20, R81.10, and R80.
  • Organizations should take immediate action to protect their environment, as this vulnerability can be exploited remotely with root privileges.
  • Censys researchers reported that 3,836 hosts globally carry the Security Management/Log Server role.
  • Organizations should patch these servers quickly and limit Trusted Clients access to specific, known internal IP addresses.



  • Check Point has recently released a critical fix for the CVE-2026-91843 vulnerability, a serious flaw that could allow attackers to execute root code without needing a login. This vulnerability was identified by Censys researchers, who found that an attacker could trigger a stack overflow by sending an extremely long username during the login process. The vulnerability has a CVSS score of 9.8, making it a critical threat.

    The affected versions of Check Point's Security Management and Log Servers that contain this vulnerability include R82.20, R82.10 Jumbo Hotfix Take 44 or lower, R82 Jumbo Hotfix Take 126 or lower, R81.20 Jumbo Hotfix Take 166 or lower, R81.10 Jumbo Hotfix Take 190 or lower, and R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS). Check Point has released the fix through its LivePatch channel, and customers with automatic updates enabled should already have protection.

    However, it is essential for organizations to take immediate action to protect their environment. This vulnerability could allow an unauthenticated attacker to remotely execute arbitrary code with root privileges through the login process. According to Check Point, the attack path works only when customers use the Trusted Clients setting, which controls access to the management server through SmartConsole.

    Censys researchers reported that 3,836 hosts globally carry the Security Management/Log Server role, identified by the Security Internal Communication (SIC) identity. Check Point assigns management servers by default rather than by version, since build and Jumbo Hotfix level are not visible in passive scan data. Therefore, it is crucial for organizations to check their update status and apply the fix if required.

    As an additional security measure, organizations should follow the recommendations in the Check Point Management and Gateway hardening best practices guide. They should also limit Trusted Clients access on the management server to specific, known internal IP addresses. Organizations should patch these servers quickly, as they manage firewall and admin access, and teams should take prompt action to protect their environment.

    While there is currently no indication that this vulnerability has been exploited in the wild, its critical severity and potential impact make it essential for organizations to take immediate action. Check Point has released the fix, and customers with automatic updates enabled should already have protection. However, it is still crucial for organizations to take proactive measures to protect their environment.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Check-Point-Fixes-Critical-CVE-2026-91843-a-Critical-Vulnerability-Allowing-Root-Code-Execution-ehn.shtml

  • https://securityaffairs.com/199279/security/check-point-fixes-critical-cve-2026-91843-allowing-root-code-execution.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-91843

  • https://www.cvedetails.com/cve/CVE-2026-91843/


  • Published: Fri Sep 18 03:46:36 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us