VMTech
Discuss a project

Check Point fixes unauthenticated root execution flaw in management servers

Check Point fixes unauthenticated root execution flaw in management servers

Check Point has released a LivePatch fix for CVE-2026-91843, a critical vulnerability in its Security Management and Log Servers that can allow an unauthenticated network attacker to execute code as root. Check Point rates the issue 9.8 out of 10 on the CVSS scale and says it has no indication that the flaw has been exploited.

The affected management platform controls firewall policy and administrator access. Check Point says the vulnerable path is limited to the Trusted Clients setting, which defines the hosts permitted to connect to the management server through SmartConsole.

Overflow before authentication

CVE-2026-91843 is a stack overflow in the login process, meaning a request can reach the vulnerable code before user authentication takes place. Censys said the overflow can be triggered by a login request containing a very long username.

Check Point published its notice on September 16, 2026, and directed customers to the LivePatch remediation in advisory sk1000155. CISA recorded exploitation as “none” in its assessment attached to the CVE record on September 17, while the vulnerability was not listed in CISA’s Known Exploited Vulnerabilities catalog as of the September 16 catalog release. Censys also said no public proof-of-concept exploit was available as of September 16.

Versions and deployments at risk

Check Point lists R82.10 with Jumbo Hotfix Take 44 or below, R82 with Take 126 or below, R81.20 with Take 166 or below, and R81.10 with Take 190 or below as affected. R81, R80.40, R80.30, R80.20, R80.10 and R80 are also affected and are end of support.

Although R82.20 does not appear in the CVE record, Check Point confirmed that every R82.20 build is vulnerable; Censys said no Jumbo Hotfix yet protects that branch. Check Point also confirmed exposure for standalone deployments, Log Servers and Multi-Domain servers. Hosted Smart-1 Cloud is not affected because the fix is already in place, NHS England Digital said, citing the advisory.

Censys identified 3,836 hosts worldwide presenting the default identity used by Check Point management and log servers. It stressed that this is a count of role presence, not a confirmed count of vulnerable systems, because scan data does not reveal build or hotfix levels.

Actions for administrators

Organizations should apply the LivePatch from sk1000155 to every Security Management Server and Log Server. Environments with automatic updates enabled should still confirm installation with the cplp list command, which displays installed LivePatches and their status.

Check Point also recommends limiting Trusted Clients to known, trusted hosts rather than any IP address and avoiding direct internet exposure for management access. Its hardening guidance places the setting in SmartConsole under Manage & Settings, Permissions & Administrators and Trusted Clients, and states that a VPN is required when remote access is needed.

For businesses, the immediate task is to validate patch deployment and management-plane access controls across every affected role, including R82.20 and standalone systems, instead of treating enabled automatic updates as proof of protection.

#cybersecurity#checkpoint#vulnerability#patchmanagement
Open analytics
On the site 1 views
min read 3 18.09.2026
Instagram

Check Point fixes unauthenticated root execution flaw in management servers

Open the post on Instagram ↗