AI Weekly Malaysia

Back to items Summaries

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

ID
25848
Status
summarized
Published
18 Sep 2026, 2:08 AM
Fetched
18 Sep 2026, 12:41 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/critical-check-point-management-server.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
18 Sep 2026, 12:44 PM
Tags
Audience
developers

What happened

A CVSS 9.8 stack overflow vulnerability (CVE-2026-91843) in Check Point Security Management and Log Servers allows unauthenticated remote attackers to execute code as root by sending a login request with a very long username. The flaw exists in the Trusted Clients login path, affects R82.10 (Jumbo Hotfix Take ≤44), R82 (≤126), and R81.20, and Check Point has shipped a LivePatch fix (advisory sk1000155) with no known exploitation in the wild as of September 17, 2026.

Why it matters

If your organization runs Check Point Security Management Servers, verify whether automatic LivePatch updates are enabled and confirm you are above the affected Jumbo Hotfix Take levels immediately. For most builders not managing Check Point infrastructure directly, this requires no action.

Discussion angle

Brief mention only: note that pre-authentication stack overflows in management planes remain a pattern worth watching, but this specific CVE is actionable only for teams operating Check Point firewalls.

Top