CVE-2026-91843: 
CloudGuard Management Server Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-91843 is a critical stack-based buffer overflow vulnerability in Check Point Quantum Security Management and Log Servers that allows unauthenticated remote attackers to execute arbitrary code with root privileges. The flaw exists in the login process and requires no credentials or user interaction to exploit. It was disclosed on September 16, 2026, with a patch made available the same day. Affected versions span a wide range including R80 through R82.10 across multiple Jumbo Hotfix takes, with several versions already at End of Support (EOS). It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Check Point SK).

Détails techniques

The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow), occurring during the unauthenticated login process of Check Point's Security Management and Log Servers. An attacker can send a specially crafted network request to the login endpoint, triggering a stack overflow that overwrites control flow data and enables arbitrary code execution. Because the flaw is pre-authentication and requires no privileges or user interaction, it is fully automatable and exploitable over the network with low complexity. No specific technical write-up or PoC with working exploit code has been confirmed publicly; a GitHub repository claiming to contain a PoC was assessed as containing only template/placeholder content with no actual exploit code (GitHub Advisory, Check Point SK).

Impact

Successful exploitation grants an unauthenticated remote attacker root-level code execution on the affected Check Point Security Management or Log Server, resulting in complete compromise of confidentiality, integrity, and availability. Because Security Management Servers control firewall policy and network security configurations across an organization, a compromised management server could enable an attacker to alter firewall rules, exfiltrate sensitive network topology and policy data, pivot to managed security gateways, and potentially disable security controls across the entire protected environment. The technical impact is rated as "total" by NVD SSVC analysis (GitHub Advisory, Check Point SK).

Exploitabilité

The vulnerability is automatable (no user interaction required) and exploitable over the network without authentication, making it highly attractive for mass exploitation. A GitHub repository (https://github.com/HORKimhab/CVE-2026-91843) was flagged as a potential PoC but was assessed as non-functional — containing only boilerplate template content with no actual exploit code. Exploitation has been reported in the wild by sources including cyberworldops.eu, though no specific threat actor attribution has been confirmed. The EPSS score is approximately 0.5%, and the vulnerability is not currently listed in the CISA KEV catalog based on available data. NVD SSVC classifies exploitation status as "none" confirmed at time of analysis, though community reporting suggests active exploitation attempts (GitHub Advisory, Feedly).

Étapes d’exploitation

  1. Reconnaissance: Identify internet-facing Check Point Security Management Servers or Log Servers using tools like Shodan or Censys, filtering for known Check Point management ports (e.g., TCP 18190, 19009, or web management interfaces). Confirm version information where possible to identify vulnerable Jumbo Hotfix takes.
  2. Target the login endpoint: Send a crafted network request to the unauthenticated login service exposed by the Security Management or Log Server. This endpoint is accessible without credentials.
  3. Trigger the stack overflow: Craft an oversized or malformed input in the login request parameters that exceeds the allocated stack buffer, overwriting the return address or control flow data on the stack.
  4. Control execution flow: Use standard stack overflow exploitation techniques (e.g., ROP chains or shellcode injection) to redirect execution to attacker-controlled code. The process runs as root, so no privilege escalation is needed.
  5. Achieve root code execution: Execute arbitrary commands or deploy a persistent backdoor on the management server, then leverage root access to modify firewall policies, exfiltrate configuration data, or pivot to managed network devices (Check Point SK, GitHub Advisory).

Indicateurs de compromis

  • Network: Unexpected or malformed connection attempts to Check Point management server login ports (e.g., TCP 18190, 19009) from external or untrusted IP addresses; unusual outbound connections from the management server to unknown external hosts.
  • Logs: Crash logs or core dumps associated with the login service daemon on the Security Management or Log Server; repeated failed or malformed login attempts in management server authentication logs; unexpected process termination events in system logs.
  • File System: Unexpected new files, scripts, or binaries in system directories (e.g., /tmp, /var, /root); new cron jobs or startup scripts added by the root account; unauthorized SSH keys added to /root/.ssh/authorized_keys.
  • Process: Unusual child processes spawned by the Check Point login/management daemon (e.g., /bin/bash, curl, wget, python, nc); unexpected network listeners opened on the management server; processes running as root that are not part of normal Check Point operations (Check Point SK).

Atténuation et solutions de contournement

Check Point released patches via Jumbo Hotfix updates: apply Jumbo Hotfix Take 191 or above for R81.10, Take 167 or above for R81.20, Take 127 or above for R82, and Take 45 or above for R82.10. Versions R80, R80.10, R80.20, R80.30, R80.40, and R81 are End of Support and should be upgraded to a supported release immediately. Check Point also provided a LivePatch mechanism for rapid remediation without a full system restart. As an interim workaround where patching is not immediately feasible, restrict network-level access to management server login ports using firewall ACLs to limit exposure to trusted management networks only (Check Point SK, GitHub Advisory).

Réactions de la communauté

The vulnerability received significant coverage across security media, with outlets including BleepingComputer, The Hacker News, SecurityWeek, Security Affairs, Heise, and GBHackers reporting on the critical flaw. Community discussion was active on Reddit (r/checkpoint, r/blueteamsec, r/InfoSecNews) and Mastodon/Infosec.exchange, with practitioners noting this is reportedly the fifth critical management-plane flaw from Check Point in a short period, raising concerns about the security posture of the product line. The Canadian Centre for Cyber Security (CCCS) and NHS Digital issued advisories urging immediate patching. SOCRadar and 4sysops published dedicated analysis pieces, and Check Point's own threat intelligence report for the week of September 21, 2026 referenced the vulnerability (BleepingComputer, The Hacker News, SecurityWeek, Check Point Research).

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté CloudGuard Management Server Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-93616CRITICAL9.8
  • CloudGuard Management Server logoCloudGuard Management Server
  • cpe:2.3:a:checkpoint:quantum_security_management
OuiOuiSep 22, 2026
CVE-2026-91843CRITICAL9.8
  • CloudGuard Management Server logoCloudGuard Management Server
  • cpe:2.3:a:checkpoint:quantum_security_management
NonNonSep 16, 2026
CVE-2026-16232CRITICAL9.3
  • CloudGuard Management Server logoCloudGuard Management Server
  • cpe:2.3:a:checkpoint:jhf
OuiOuiJul 22, 2026
CVE-2026-62144CRITICAL9.1
  • CloudGuard Management Server logoCloudGuard Management Server
  • cpe:2.3:a:checkpoint:quantum_security_management
NonNonJul 22, 2026
CVE-2026-62145HIGH7.5
  • CloudGuard Management Server logoCloudGuard Management Server
  • cpe:2.3:a:checkpoint:quantum_security_management
NonNonJul 22, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités