CVE-2026-91843: 
CloudGuard Management Server 脆弱性の分析と軽減

概要

CVE-2026-91843 is a critical stack-based buffer overflow vulnerability in Check Point Quantum Security Management and Log Servers that allows unauthenticated remote attackers to execute arbitrary code with root privileges. The flaw exists in the login process and requires no credentials or user interaction to exploit. It was disclosed on September 16, 2026, with a patch made available the same day. Affected versions span a wide range including R80 through R82.10 across multiple Jumbo Hotfix takes, with several versions already at End of Support (EOS). It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Check Point SK).

技術的な詳細

The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow), occurring during the unauthenticated login process of Check Point's Security Management and Log Servers. An attacker can send a specially crafted network request to the login endpoint, triggering a stack overflow that overwrites control flow data and enables arbitrary code execution. Because the flaw is pre-authentication and requires no privileges or user interaction, it is fully automatable and exploitable over the network with low complexity. No specific technical write-up or PoC with working exploit code has been confirmed publicly; a GitHub repository claiming to contain a PoC was assessed as containing only template/placeholder content with no actual exploit code (GitHub Advisory, Check Point SK).

影響

Successful exploitation grants an unauthenticated remote attacker root-level code execution on the affected Check Point Security Management or Log Server, resulting in complete compromise of confidentiality, integrity, and availability. Because Security Management Servers control firewall policy and network security configurations across an organization, a compromised management server could enable an attacker to alter firewall rules, exfiltrate sensitive network topology and policy data, pivot to managed security gateways, and potentially disable security controls across the entire protected environment. The technical impact is rated as "total" by NVD SSVC analysis (GitHub Advisory, Check Point SK).

エクスプロイト可能性

The vulnerability is automatable (no user interaction required) and exploitable over the network without authentication, making it highly attractive for mass exploitation. A GitHub repository (https://github.com/HORKimhab/CVE-2026-91843) was flagged as a potential PoC but was assessed as non-functional — containing only boilerplate template content with no actual exploit code. Exploitation has been reported in the wild by sources including cyberworldops.eu, though no specific threat actor attribution has been confirmed. The EPSS score is approximately 0.5%, and the vulnerability is not currently listed in the CISA KEV catalog based on available data. NVD SSVC classifies exploitation status as "none" confirmed at time of analysis, though community reporting suggests active exploitation attempts (GitHub Advisory, Feedly).

エクスプロイテーションのステップ

  1. Reconnaissance: Identify internet-facing Check Point Security Management Servers or Log Servers using tools like Shodan or Censys, filtering for known Check Point management ports (e.g., TCP 18190, 19009, or web management interfaces). Confirm version information where possible to identify vulnerable Jumbo Hotfix takes.
  2. Target the login endpoint: Send a crafted network request to the unauthenticated login service exposed by the Security Management or Log Server. This endpoint is accessible without credentials.
  3. Trigger the stack overflow: Craft an oversized or malformed input in the login request parameters that exceeds the allocated stack buffer, overwriting the return address or control flow data on the stack.
  4. Control execution flow: Use standard stack overflow exploitation techniques (e.g., ROP chains or shellcode injection) to redirect execution to attacker-controlled code. The process runs as root, so no privilege escalation is needed.
  5. Achieve root code execution: Execute arbitrary commands or deploy a persistent backdoor on the management server, then leverage root access to modify firewall policies, exfiltrate configuration data, or pivot to managed network devices (Check Point SK, GitHub Advisory).

妥協の兆候

  • Network: Unexpected or malformed connection attempts to Check Point management server login ports (e.g., TCP 18190, 19009) from external or untrusted IP addresses; unusual outbound connections from the management server to unknown external hosts.
  • Logs: Crash logs or core dumps associated with the login service daemon on the Security Management or Log Server; repeated failed or malformed login attempts in management server authentication logs; unexpected process termination events in system logs.
  • File System: Unexpected new files, scripts, or binaries in system directories (e.g., /tmp, /var, /root); new cron jobs or startup scripts added by the root account; unauthorized SSH keys added to /root/.ssh/authorized_keys.
  • Process: Unusual child processes spawned by the Check Point login/management daemon (e.g., /bin/bash, curl, wget, python, nc); unexpected network listeners opened on the management server; processes running as root that are not part of normal Check Point operations (Check Point SK).

軽減策と回避策

Check Point released patches via Jumbo Hotfix updates: apply Jumbo Hotfix Take 191 or above for R81.10, Take 167 or above for R81.20, Take 127 or above for R82, and Take 45 or above for R82.10. Versions R80, R80.10, R80.20, R80.30, R80.40, and R81 are End of Support and should be upgraded to a supported release immediately. Check Point also provided a LivePatch mechanism for rapid remediation without a full system restart. As an interim workaround where patching is not immediately feasible, restrict network-level access to management server login ports using firewall ACLs to limit exposure to trusted management networks only (Check Point SK, GitHub Advisory).

コミュニティの反応

The vulnerability received significant coverage across security media, with outlets including BleepingComputer, The Hacker News, SecurityWeek, Security Affairs, Heise, and GBHackers reporting on the critical flaw. Community discussion was active on Reddit (r/checkpoint, r/blueteamsec, r/InfoSecNews) and Mastodon/Infosec.exchange, with practitioners noting this is reportedly the fifth critical management-plane flaw from Check Point in a short period, raising concerns about the security posture of the product line. The Canadian Centre for Cyber Security (CCCS) and NHS Digital issued advisories urging immediate patching. SOCRadar and 4sysops published dedicated analysis pieces, and Check Point's own threat intelligence report for the week of September 21, 2026 referenced the vulnerability (BleepingComputer, The Hacker News, SecurityWeek, Check Point Research).

関連情報


ソース: このレポートは AI を使用して生成されました

関連 CloudGuard Management Server 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-93616CRITICAL9.8
  • CloudGuard Management Server logoCloudGuard Management Server
  • cpe:2.3:a:checkpoint:quantum_security_management
はいはいSep 22, 2026
CVE-2026-91843CRITICAL9.8
  • CloudGuard Management Server logoCloudGuard Management Server
  • cpe:2.3:a:checkpoint:quantum_security_management
いいえいいえSep 16, 2026
CVE-2026-16232CRITICAL9.3
  • CloudGuard Management Server logoCloudGuard Management Server
  • cpe:2.3:a:checkpoint:jhf
はいはいJul 22, 2026
CVE-2026-62144CRITICAL9.1
  • CloudGuard Management Server logoCloudGuard Management Server
  • cpe:2.3:a:checkpoint:quantum_security_management
いいえいいえJul 22, 2026
CVE-2026-62145HIGH7.5
  • CloudGuard Management Server logoCloudGuard Management Server
  • cpe:2.3:a:checkpoint:quantum_security_management
いいえいいえJul 22, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者