Check Point Security Management and Log Servers stack overflow security flaw (CVE-2026-91843)
Vulnerability
Summary
Hide ▲
Show ▼
Check Point Security Management and Log Servers are affected by CVE-2026-91843, a critical stack overflow that can let unauthenticated attackers run code as root over the network. Check Point says a LivePatch fix is available and has no indication of exploitation in the wild. The flaw affects R82.10, R82, R81.20, R81.10 and older branches, and Check Point also said R82.20, standalone deployments, Log Servers, and Multi-Domain servers are vulnerable. Administrators should install sk1000155 and restrict Trusted Clients to trusted hosts.
Related Happenings
Check Point Security Gateways and Security Management Server VPN certificate flaws (multiple vulnerabilities)
Vulnerability
H score53
First: 10.09.2026 14:45
Last: 10.09.2026 14:45
Sources 1
About this happening:
Check Point Security Gateways and Security Management Server are affected by two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that can let an...
Check Point Security Gateways and Security Management Server VPN certificate flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: Check Point Security Gateways and Security Management Server are affected by two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that can let an...
Check Point VPN certificate mitigation guidance
Advisory/Mitigation
H score53
First: 10.09.2026 14:45
Last: 10.09.2026 14:45
Sources 1
About this happening:
Check Point directed affected customers to Live Patch or the latest Jumbo Hotfix for its VPN certificate flaws, with rollout beginning on September 9. The guidance...
Check Point VPN certificate mitigation guidance
Advisory/MitigationAbout this happening: Check Point directed affected customers to Live Patch or the latest Jumbo Hotfix for its VPN certificate flaws, with rollout beginning on September 9. The guidance...
SmartConsole actively exploited authentication bypass (CVE-2026-16232)
Vulnerability
H score43
First: 23.07.2026 11:13
Last: 23.07.2026 11:13
Sources 1
About this happening:
Check Point addressed CVE-2026-16232, a zero-day authentication bypass in SmartConsole affecting Security Management and Multi-Domain Management products....
SmartConsole actively exploited authentication bypass (CVE-2026-16232)
VulnerabilityAbout this happening: Check Point addressed CVE-2026-16232, a zero-day authentication bypass in SmartConsole affecting Security Management and Multi-Domain Management products....
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/Mitigation
H score46
First: 20.02.2026 19:02
Last: 20.02.2026 19:02
Sources 1
About this happening:
CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/MitigationAbout this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA updates KEV entry for CVE-2026-1731
Public Sector Action
H score36
First: 20.02.2026 17:45
Last: 20.02.2026 17:45
Sources 1
About this happening:
CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...
CISA updates KEV entry for CVE-2026-1731
Public Sector ActionAbout this happening: CISA updated its KEV catalog entry for CVE-2026-1731, confirming the flaw has been used in ransomware campaigns and elevating its government-tracked risk. The upda...
Timeline
-
18.09.2026 03:00 1 articles · 5h ago
Check Point confirms broader vulnerable versions and deployment types
Campaign Scope UpdateCheck Point confirms that R82.20, standalone deployments, Log Servers, and Multi-Domain servers are vulnerable, and says customers who need fixes for out-of-support versions should open a ticket with Check Point support.
Show sources
- Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root — thehackernews.com — 17.09.2026 21:08
-
17.09.2026 03:00 1 articles · 1d ago
CISA records no exploitation for CVE-2026-91843
Victim Impact UpdateCISA records exploitation as none for CVE-2026-91843, and Check Point says it has not received any reports of exploitation in the wild.
Show sources
- Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root — thehackernews.com — 17.09.2026 21:08
-
16.09.2026 03:00 1 articles · 2d ago
Check Point discloses CVE-2026-91843 in Security Management and Log Servers
Initial DisclosureCheck Point discloses CVE-2026-91843 in Security Management and Log Servers, a critical network-reachable stack overflow in the login process that can let an unauthenticated attacker run code as root, and says customers with automatic updates enabled are already protected while everyone else should apply the LivePatch fix in sk1000155 immediately.
Show sources
- Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root — thehackernews.com — 17.09.2026 21:08
-
16.09.2026 03:00 2 articles · 2d ago
Trusted Clients path and long username trigger the stack overflow
Technical Analysis UpdateCheck Point says the vulnerable path runs only through the Trusted Clients setting that controls which hosts may connect through SmartConsole, and Censys says the stack overflow is triggered by a login request carrying a very long username.
Show sources
- Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root — thehackernews.com — 17.09.2026 21:08
- Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root — thehackernews.com — 17.09.2026 21:08