CVE-2026-91843: 
CloudGuard Management Server vulnerability analysis and mitigation

Overview

CVE-2026-91843 is a critical stack-based buffer overflow vulnerability in Check Point Quantum Security Management and Log Servers that allows unauthenticated remote attackers to execute arbitrary code with root privileges. The flaw exists in the login process and requires no credentials or user interaction to exploit. It was disclosed on September 16, 2026, with a patch made available the same day. Affected versions span a wide range including R80 through R82.10 across multiple Jumbo Hotfix takes, with several versions already at End of Support (EOS). It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Check Point SK).

Technical details

The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow), occurring during the unauthenticated login process of Check Point's Security Management and Log Servers. An attacker can send a specially crafted network request to the login endpoint, triggering a stack overflow that overwrites control flow data and enables arbitrary code execution. Because the flaw is pre-authentication and requires no privileges or user interaction, it is fully automatable and exploitable over the network with low complexity. No specific technical write-up or PoC with working exploit code has been confirmed publicly; a GitHub repository claiming to contain a PoC was assessed as containing only template/placeholder content with no actual exploit code (GitHub Advisory, Check Point SK).

Impact

Successful exploitation grants an unauthenticated remote attacker root-level code execution on the affected Check Point Security Management or Log Server, resulting in complete compromise of confidentiality, integrity, and availability. Because Security Management Servers control firewall policy and network security configurations across an organization, a compromised management server could enable an attacker to alter firewall rules, exfiltrate sensitive network topology and policy data, pivot to managed security gateways, and potentially disable security controls across the entire protected environment. The technical impact is rated as "total" by NVD SSVC analysis (GitHub Advisory, Check Point SK).

Exploitability

The vulnerability is automatable (no user interaction required) and exploitable over the network without authentication, making it highly attractive for mass exploitation. A GitHub repository (https://github.com/HORKimhab/CVE-2026-91843) was flagged as a potential PoC but was assessed as non-functional — containing only boilerplate template content with no actual exploit code. Exploitation has been reported in the wild by sources including cyberworldops.eu, though no specific threat actor attribution has been confirmed. The EPSS score is approximately 0.5%, and the vulnerability is not currently listed in the CISA KEV catalog based on available data. NVD SSVC classifies exploitation status as "none" confirmed at time of analysis, though community reporting suggests active exploitation attempts (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Check Point Security Management Servers or Log Servers using tools like Shodan or Censys, filtering for known Check Point management ports (e.g., TCP 18190, 19009, or web management interfaces). Confirm version information where possible to identify vulnerable Jumbo Hotfix takes.
  2. Target the login endpoint: Send a crafted network request to the unauthenticated login service exposed by the Security Management or Log Server. This endpoint is accessible without credentials.
  3. Trigger the stack overflow: Craft an oversized or malformed input in the login request parameters that exceeds the allocated stack buffer, overwriting the return address or control flow data on the stack.
  4. Control execution flow: Use standard stack overflow exploitation techniques (e.g., ROP chains or shellcode injection) to redirect execution to attacker-controlled code. The process runs as root, so no privilege escalation is needed.
  5. Achieve root code execution: Execute arbitrary commands or deploy a persistent backdoor on the management server, then leverage root access to modify firewall policies, exfiltrate configuration data, or pivot to managed network devices (Check Point SK, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected or malformed connection attempts to Check Point management server login ports (e.g., TCP 18190, 19009) from external or untrusted IP addresses; unusual outbound connections from the management server to unknown external hosts.
  • Logs: Crash logs or core dumps associated with the login service daemon on the Security Management or Log Server; repeated failed or malformed login attempts in management server authentication logs; unexpected process termination events in system logs.
  • File System: Unexpected new files, scripts, or binaries in system directories (e.g., /tmp, /var, /root); new cron jobs or startup scripts added by the root account; unauthorized SSH keys added to /root/.ssh/authorized_keys.
  • Process: Unusual child processes spawned by the Check Point login/management daemon (e.g., /bin/bash, curl, wget, python, nc); unexpected network listeners opened on the management server; processes running as root that are not part of normal Check Point operations (Check Point SK).

Mitigation and workarounds

Check Point released patches via Jumbo Hotfix updates: apply Jumbo Hotfix Take 191 or above for R81.10, Take 167 or above for R81.20, Take 127 or above for R82, and Take 45 or above for R82.10. Versions R80, R80.10, R80.20, R80.30, R80.40, and R81 are End of Support and should be upgraded to a supported release immediately. Check Point also provided a LivePatch mechanism for rapid remediation without a full system restart. As an interim workaround where patching is not immediately feasible, restrict network-level access to management server login ports using firewall ACLs to limit exposure to trusted management networks only (Check Point SK, GitHub Advisory).

Community reactions

The vulnerability received significant coverage across security media, with outlets including BleepingComputer, The Hacker News, SecurityWeek, Security Affairs, Heise, and GBHackers reporting on the critical flaw. Community discussion was active on Reddit (r/checkpoint, r/blueteamsec, r/InfoSecNews) and Mastodon/Infosec.exchange, with practitioners noting this is reportedly the fifth critical management-plane flaw from Check Point in a short period, raising concerns about the security posture of the product line. The Canadian Centre for Cyber Security (CCCS) and NHS Digital issued advisories urging immediate patching. SOCRadar and 4sysops published dedicated analysis pieces, and Check Point's own threat intelligence report for the week of September 21, 2026 referenced the vulnerability (BleepingComputer, The Hacker News, SecurityWeek, Check Point Research).

Additional resources


Source: This report was generated using AI

Related CloudGuard Management Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93616CRITICAL9.8
  • CloudGuard Management Server logoCloudGuard Management Server
  • cpe:2.3:a:checkpoint:quantum_security_management
YesYesSep 22, 2026
CVE-2026-91843CRITICAL9.8
  • CloudGuard Management Server logoCloudGuard Management Server
  • cpe:2.3:a:checkpoint:quantum_security_management
NoNoSep 16, 2026
CVE-2026-16232CRITICAL9.3
  • CloudGuard Management Server logoCloudGuard Management Server
  • cpe:2.3:a:checkpoint:jhf
YesYesJul 22, 2026
CVE-2026-62144CRITICAL9.1
  • CloudGuard Management Server logoCloudGuard Management Server
  • cpe:2.3:a:checkpoint:quantum_security_management
NoNoJul 22, 2026
CVE-2026-62145HIGH7.5
  • CloudGuard Management Server logoCloudGuard Management Server
  • cpe:2.3:a:checkpoint:quantum_security_management
NoNoJul 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management