Check Point Security Management/Log Server login stack overflow CVE-2026-91843 (CVSS 9.8); LivePatch
Check Point advisory sk1000155 (disclosed 16 September 2026; NVD published same day) documents CVE-2026-91843, a stack overflow (CWE-121) in the unauthenticated login process on Security Management and Log Servers. Check Point CVSS 3.1 base 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An attacker without credentials can run arbitrary code as root over the network; Check Point states the vulnerable path runs through the Trusted Clients setting (hosts allowed to connect via SmartConsole). Vendor and CISA SSVC: no indication of in-the-wild exploitation; not in KEV as of mid-September catalog checks. Affected branches by Jumbo Hotfix Take (or older): R82.20 (apply Take 29+), R82.10 Take 44 or below, R82 Take 126 or below, R81.20 Take 166 or below; R81.10/R81/R80.x End of Support (ticket Check Point for fix or upgrade). Standalone, Log Server, and Multi-Domain deployments also vulnerable per vendor confirmation (THN update 18 Sep). Smart-1 Cloud hosted management is not affected (fix already deployed). Remediation: LivePatch per sk1000155; customers with automatic updates (sk175504) already protected. Distinct from desk card checkpoint-vpn-cert-20260910 (VPN CVE-2026-85102/85103). Primary: Check Point sk1000155; secondary: NVD / Censys advisory.
- Product
- Check Point Quantum Security Management Server, Log Server, Multi-Domain / standalone management
- Versions
- R82.20 before LivePatch Take 29; R82.10 Jumbo Take ≤44; R82 Take ≤126; R81.20 Take ≤166; R81.10/R81/R80.x EOS — see sk1000155. Smart-1 Cloud not affected.
- CVSS
- (CVSS 3.1, Check Point Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Apply LivePatch from sk1000155 (Takes: R82.20 T29+, R82.10 T28+, R82 T28+, R81.20 T28+); enable automatic updates (sk175504); restrict Trusted Clients; EOS branches: upgrade or open Check Point support ticket
Primary: Check Point sk1000155 — CVE-2026-91843 Security Management/Log Server (16 Sep 2026) · Vendor: Check Point Support — sk1000155 LivePatch · CVE: CVE-2026-91843, CVE-2026-85102 · NVD — CVE-2026-91843; also Censys advisory / CheckMates notice
