Skip to content

Security1 publisher2 min readPublished

Unauthenticated attackers can run code as root on Check Point's Security Management Server

Check Point rates CVE-2026-91843 at 9.8 and shipped the fix through LivePatch sk1000155 on September 16. Its own CVE record leaves out R82.20, a branch the company's network security product VP says is vulnerable.

The Watch · Security desk

Illustration accompanying Unauthenticated attackers can run code as root on Check Point's Security Management Server

What happened

  • Check Point's Security Management and Log Servers carry a stack overflow in the login process, which handles requests before authentication, letting an unauthenticated attacker on the network run code as root.
  • Check Point posted the fix on its CheckMates community on September 16, 2026, said customers with automatic updates enabled are already protected, and told everyone else to apply LivePatch sk1000155.
  • Abramovich said Log Servers, Multi-Domain servers and standalone deployments that run management and gateway on one system are vulnerable as well.
  • CISA recorded exploitation as none in the assessment attached to the CVE record on September 17.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Where the Trusted Clients list accepts any IP address and management access is reachable from the internet, the pre-authentication login handler sits in front of any host that can route to it.
  • constraint Censys says no Jumbo Hotfix protects R82.20 yet, so LivePatch is the route for that branch, and the end-of-support branches need a Check Point support ticket to get a fix at all.
  • contradiction An estate audited against the CVE record's branch list will pass R82.20 servers as unaffected, and Check Point's network security product VP and Censys both say those servers are vulnerable.
  • decision Relying on the automatic channel is now a choice with recent evidence against it: on last week's VPN certificate fixes, customers reported the package had not arrived on announcement day.

Check Point told The Hacker News that the vulnerable path runs only through Trusted Clients, the setting that controls which hosts may connect to the management server through SmartConsole [5]. Censys says the overflow is triggered by a login request carrying a very long username [4]. The company's own CVSS rating is 9.8 out of 10 [2]. Its guidance, patched or not, is to confirm Trusted Clients is limited to known trusted hosts and not set to any IP address, and to keep management access off the internet [6].

Nothing in the record points to exploitation. "At this time, there is no indication that this vulnerability has been exploited in the wild," the CheckMates notice said [8]. The flaw was not in CISA's Known Exploited Vulnerabilities catalog as of that catalog's September 16 release [10]. Censys said no public proof-of-concept exploit existed as of September 16 [11]. Aviv Abramovich, Check Point's vice president of product management for network security, told The Hacker News that the company had not received any reports of exploitation [12]. The dated statements all fall on September 16 and 17 [3].

The affected list in the CVE record is keyed to Jumbo Hotfix Take, the numbered level of the update package that collects fixes for a release: R82.10 at Take 44 or below, R82 at 126 or below, R81.20 at 166 or below, R81.10 at 190 or below, plus the end-of-support branches R81, R80.40, R80.30, R80.20, R80.10 and R80 [13]. R82.20 is not on that list, and Abramovich said R82.20 is vulnerable as well [14]. NHS England Digital, citing sk1000155, says the hosted Smart-1 Cloud service is not affected because the fix is already in place there [18].

Automatic updates has a specific meaning here, set out in sk175504: a SmartConsole checkbox under Global Properties and Data Access Control, labeled "Automatically download and install Software Blade Contracts, security updates, and other important data (highly recommended)," followed by installation of the Access Control policy [19]. LivePatch is the channel Check Point uses to push urgent security fixes to systems where that option is turned on [19]. Check Point says to confirm the fix has been installed instead of assuming it, and the cplp list command shows which LivePatches are installed and their status [20].

What to watch

  • CVE-2026-91843 appearing in CISA's KEV catalog, or a public proof-of-concept landing, either of which shortens the patch window.
  • A Jumbo Hotfix Take that covers R82.20, and a CVE record updated to list that branch.
  • Whether this LivePatch reaches automatic-update customers on the day of the announcement.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories