Connect with us

Cybersecurity

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

Published

on

A newly disclosed critical security vulnerability in Check Point Security Management and Log Server products could allow remote attackers to execute arbitrary code with root-level privileges without authenticating to the affected system.

The vulnerability, identified as CVE-2026-91843, has been assigned a CVSS score of 9.8 out of 10, making it a critical security concern for organizations using vulnerable Check Point deployments.

Security Management Servers at Risk

The flaw affects the login process of Check Point management systems and is described as a stack-based overflow that can occur before authentication is completed.

According to information provided by Check Point, the vulnerable attack path is associated with the Trusted Clients configuration. This setting determines which systems are permitted to connect to management servers through SmartConsole.

Security researchers at Censys reported that the vulnerability can be triggered by sending a login request containing an unusually long username. If successfully exploited, an attacker could potentially execute commands with root privileges on the affected server.

Check Point has released a security fix through its LivePatch mechanism and has urged customers to apply the update immediately.

The company said it currently has no evidence that CVE-2026-91843 has been exploited in real-world attacks. CISA’s assessment associated with the CVE also indicated no known exploitation at the time of publication.

Which Check Point Versions Are Affected?

Check Point’s vulnerability information identifies several affected software branches based on their installed Jumbo Hotfix Take level.

Affected versions include:

  • R82.10: Jumbo Hotfix Take 44 and earlier
  • R82: Jumbo Hotfix Take 126 and earlier
  • R81.20: Jumbo Hotfix Take 166 and earlier
  • R81.10: Jumbo Hotfix Take 190 and earlier
  • Older R81, R80.40, R80.30, R80.20, R80.10 and R80 releases are also affected and are already out of support.

Check Point has also confirmed that R82.20 is vulnerable, although the CVE record does not currently list that branch. Censys reported that all R82.20 builds are affected and that a corresponding Jumbo Hotfix was not yet available for that release at the time of its advisory.

The vulnerability is not limited to conventional Security Management Server installations. Check Point has confirmed that Log Servers, Multi-Domain Servers and standalone deployments can also be affected.

The hosted Smart-1 Cloud service is not impacted because the necessary security fix has already been applied.

For customers running unsupported software versions, Check Point said a fix is available through its support process.

Administrators Urged to Take Immediate Action

Organizations using affected Check Point products should prioritize remediation rather than waiting for signs of exploitation.

Administrators should:

  1. Install the LivePatch update specified in Check Point security advisory sk1000155.
  2. Verify that the patch has actually been installed, even when automatic updates are enabled.
  3. Use the cplp list command to check installed LivePatch packages and their status.
  4. Review the Trusted Clients configuration and restrict access to known, authorized systems.
  5. Avoid configuring Trusted Clients to allow connections from unrestricted IP addresses.
  6. Do not expose management interfaces directly to the public internet.
  7. Use appropriate secure remote-access controls, including VPN protection where required.

Check Point’s guidance emphasizes that automatic updates do not necessarily mean a security fix will appear immediately on every system. Administrators should therefore verify the update status rather than relying solely on the automatic-update setting.

Internet-Exposed Management Systems Remain a Concern

The Trusted Clients configuration is particularly important because the vulnerable attack path depends on access through this setting.

Check Point’s hardening guidance recommends limiting management access to trusted systems and avoiding direct exposure of management interfaces to the internet.

Censys reported observing approximately 3,836 internet-facing hosts that appeared to use the default identity associated with Check Point management and log servers. However, the company stressed that this figure represents identified systems rather than a confirmed count of vulnerable installations because publicly visible scan data does not reveal the exact software build or hotfix level.

Latest in a Series of Critical Check Point Management Issues

CVE-2026-91843 follows several other serious vulnerabilities affecting Check Point management infrastructure in recent months.

One of them, CVE-2026-16232, involved an authentication bypass affecting SmartConsole and was reported as exploited in July. Another vulnerability, CVE-2026-62144, was also disclosed around the same period but was not reported as exploited.

Additional vulnerabilities included CVE-2026-18574, an authentication bypass capable of enabling command execution, and CVE-2026-85103, a heap-overflow vulnerability involving VPN certificate processing.

The emergence of multiple vulnerabilities affecting management infrastructure highlights the importance of keeping Check Point systems patched, restricting management access and regularly reviewing security configurations.

What Organizations Should Know

CVE-2026-91843 presents a particularly serious risk because successful exploitation could provide an unauthenticated attacker with root-level code execution on a vulnerable management or logging server.

Although Check Point has stated that it has no indication of exploitation, organizations should not wait for evidence of active attacks before applying the available security updates.

Security teams should identify affected systems, verify their Jumbo Hotfix levels, review Trusted Clients settings and ensure management interfaces are not unnecessarily exposed to the internet.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2026 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO