CVE-2026-91843

Published Sep 16, 2026

Last updated 3 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-91843 is a critical stack overflow vulnerability affecting Check Point's Security Management and Log Servers. This flaw occurs during the unauthenticated login process, enabling a remote attacker to execute arbitrary code with root privileges on the affected system. The vulnerability is specifically a stack-based buffer overflow (CWE-121) that can be triggered by sending a crafted login request containing an oversized username. This pre-authentication vulnerability means that an attacker does not require valid credentials or user interaction to exploit it, making any exposed instance directly at risk. Check Point has released a LivePatch (sk1000155) to address this issue, and customers with automatic updates enabled are already protected.

Description
A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
Source
cve@checkpoint.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cve@checkpoint.com
CWE-121

Social media

Hype score
Not currently trending
  1. 👉 Check Point CVE-2026-91843 güncellemesi: CISA açığın şu ana kadar istismar edilmediğini bildirdi, kritik risk LivePatch (sk1000155) ile kapatılabiliyor.

    @trsiberyazilim

    21 Sept 2026

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 💢 Check Point yönetim sunucularında CVSS 9,8 puanlı kritik açık: CVE-2026-91843, kimlik doğrulaması olmadan root yetkisiyle kod çalıştırılmasına izin veriyor. Detaylar 👇 https://t.co/cxDqfcwG7t #SiberGüvenlik #CheckPoint #CVE #Zafiyet #ZeroDay

    @trsiberyazilim

    21 Sept 2026

    46 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 Check Point Security Management RCE (CVE-2026-91843) Critical Vulnerability Alert! Check Point Security Management Server / Log Server is affected by CVE-2026-91843. 🔍 Identify Targets via ZoomEye: Search Dork: app="Check Point Firewall" Exposure: 277.2k instances

    @zoomeyebot

    19 Sept 2026

    212 Impressions

    0 Retweets

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CHECK POINT CVE-2026-91843 UNAUTHENTICATED ROOT RCE VIA LOGIN STACK OVERFLOW Check Point disclosed CVE-2026-91843: an unauthenticated remote attacker can achieve root via a stack overflow in the login process on Security Management Server, Multi-Domain Security Management,

    @DailyDarkWeb

    18 Sept 2026

    5892 Impressions

    1 Retweet

    18 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  5. 🚨 CRITICAL: Check Point management servers face a 9.8-rated flaw. 🔥 CVE-2026-91843 could allow an unauthenticated attacker to remotely execute code with root privileges on affected Security Management and Log Servers. ⚠️ CVSS 9.8 🔓 No login required 💻 Remote cod

    @xcademialtd

    18 Sept 2026

    21 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Check Point patched CVE-2026-91843, unauth root RCE in Security Mgmt Server login, all deployments vulnerable regardless of config. Restrict Trusted Clients by IP. https://t.co/75HggKmfcC

    @swif_ai

    18 Sept 2026

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution: Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed. Check Point addressed… https://t.co/opiQ7g2LbK https:

    @shah_sheikh

    18 Sept 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Check Point Security ManagementにCritical 脆弱性 CVE-2026-91843 認証不要でroot権限の任意コード実行 https://t.co/D5WCwgVKRl #セキュリティ対策Lab #security #securitynews #セキュリティ

    @securityLab_jp

    18 Sept 2026

    80 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 CRITICAL: Check Point patches CVE-2026-91843 — CVSS 9.8 flaw lets hackers run ROOT code with zero login required. 5th critical management-server flaw since July. Patch now 👇 https://t.co/C0SGPMb0gy #cybersecurity #infosec #CVE https://t.co/sirNkIRKxE

    @Xpert4Cyber

    17 Sept 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.