
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-91843 is a critical stack-based buffer overflow vulnerability in Check Point Quantum Security Management and Log Servers that allows unauthenticated remote attackers to execute arbitrary code with root privileges. The flaw exists in the login process and requires no credentials or user interaction to exploit. It was disclosed on September 16, 2026, with a patch made available the same day. Affected versions span a wide range including R80 through R82.10 across multiple Jumbo Hotfix takes, with several versions already at End of Support (EOS). It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Check Point SK).
The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow), occurring during the unauthenticated login process of Check Point's Security Management and Log Servers. An attacker can send a specially crafted network request to the login endpoint, triggering a stack overflow that overwrites control flow data and enables arbitrary code execution. Because the flaw is pre-authentication and requires no privileges or user interaction, it is fully automatable and exploitable over the network with low complexity. No specific technical write-up or PoC with working exploit code has been confirmed publicly; a GitHub repository claiming to contain a PoC was assessed as containing only template/placeholder content with no actual exploit code (GitHub Advisory, Check Point SK).
Successful exploitation grants an unauthenticated remote attacker root-level code execution on the affected Check Point Security Management or Log Server, resulting in complete compromise of confidentiality, integrity, and availability. Because Security Management Servers control firewall policy and network security configurations across an organization, a compromised management server could enable an attacker to alter firewall rules, exfiltrate sensitive network topology and policy data, pivot to managed security gateways, and potentially disable security controls across the entire protected environment. The technical impact is rated as "total" by NVD SSVC analysis (GitHub Advisory, Check Point SK).
The vulnerability is automatable (no user interaction required) and exploitable over the network without authentication, making it highly attractive for mass exploitation. A GitHub repository (https://github.com/HORKimhab/CVE-2026-91843) was flagged as a potential PoC but was assessed as non-functional — containing only boilerplate template content with no actual exploit code. Exploitation has been reported in the wild by sources including cyberworldops.eu, though no specific threat actor attribution has been confirmed. The EPSS score is approximately 0.5%, and the vulnerability is not currently listed in the CISA KEV catalog based on available data. NVD SSVC classifies exploitation status as "none" confirmed at time of analysis, though community reporting suggests active exploitation attempts (GitHub Advisory, Feedly).
/tmp, /var, /root); new cron jobs or startup scripts added by the root account; unauthorized SSH keys added to /root/.ssh/authorized_keys./bin/bash, curl, wget, python, nc); unexpected network listeners opened on the management server; processes running as root that are not part of normal Check Point operations (Check Point SK).Check Point released patches via Jumbo Hotfix updates: apply Jumbo Hotfix Take 191 or above for R81.10, Take 167 or above for R81.20, Take 127 or above for R82, and Take 45 or above for R82.10. Versions R80, R80.10, R80.20, R80.30, R80.40, and R81 are End of Support and should be upgraded to a supported release immediately. Check Point also provided a LivePatch mechanism for rapid remediation without a full system restart. As an interim workaround where patching is not immediately feasible, restrict network-level access to management server login ports using firewall ACLs to limit exposure to trusted management networks only (Check Point SK, GitHub Advisory).
The vulnerability received significant coverage across security media, with outlets including BleepingComputer, The Hacker News, SecurityWeek, Security Affairs, Heise, and GBHackers reporting on the critical flaw. Community discussion was active on Reddit (r/checkpoint, r/blueteamsec, r/InfoSecNews) and Mastodon/Infosec.exchange, with practitioners noting this is reportedly the fifth critical management-plane flaw from Check Point in a short period, raising concerns about the security posture of the product line. The Canadian Centre for Cyber Security (CCCS) and NHS Digital issued advisories urging immediate patching. SOCRadar and 4sysops published dedicated analysis pieces, and Check Point's own threat intelligence report for the week of September 21, 2026 referenced the vulnerability (BleepingComputer, The Hacker News, SecurityWeek, Check Point Research).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"