Check Point Systems Vulnerable to Remote Code Execution with Root Privileges
Tech
◐ Centre sources only
2d ago

Check Point Systems Vulnerable to Remote Code Execution with Root Privileges

AI-synthesized · Bias removed · Facts only
2 sources: 0 left · 2 center · 0 right
Image: Thehackernews

Check Point Software has addressed a critical vulnerability, tracked as CVE-2026-91843 and rated 9.8 out of 10 on the CVSS scale, that allows unauthenticated attackers to execute code with root privileges on the company’s Security Management and Log Servers. The flaw is a stack overflow in the login process triggered by a long username submitted through the Trusted Clients setting. Check Point released a fix via LivePatch on September 16, 2026, and states there is currently no evidence of exploitation.

The vulnerability affects several branches of Check Point software, including R82.10 with Jumbo Hotfix Take 44 or below, R82 with Jumbo Hotfix Take 126 or below, R81.20 with Jumbo Hotfix Take 166 or below, and R81.10 with Jumbo Hotfix Take 190 or below. Older branches R81, R80.40, R80.30, R80.20, R80.10, and R80 are also affected, though end of support. R82.20 is also vulnerable, despite not being listed in the initial CVE record. Standalone deployments, Log Servers, and Multi-Domain servers are impacted. The hosted Smart-1 Cloud service is not affected, as the fix has already been applied.

Censys reported no public proof-of-concept exploit existed as of September 16, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) had not added the vulnerability to its Known Exploited Vulnerabilities catalog as of September 17. Check Point’s Aviv Abramovich stated the company has not received any reports of exploitation. While automatic updates have already protected many systems, Check Point urges all customers to apply the LivePatch fix detailed in advisory sk1000155.

What is not yet known

  • Whether any attackers attempted to exploit the vulnerability before the patch was released.
  • The specific details of how the stack overflow is triggered beyond the mention of a long username.
Was this useful?

Read the original coverage

💬 Comments

📜 Comment Policy