Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaw in Check Point Servers Enables Code Execution

Critical Flaw in Check Point Servers Enables Code Execution

Posted on September 18, 2026 By CWS

A significant vulnerability has been identified in Check Point’s Security Management and Log Servers, which could permit attackers to execute code as root without needing login credentials. This flaw, present in the servers’ network operations, poses a critical security risk.

Details of the Vulnerability

The flaw resides within the Security Management Server, which oversees firewall policies and administrator access. According to Check Point, the vulnerability is linked to the Trusted Clients setting within the SmartConsole, which manages connections to the management server. A patch has been issued via Check Point’s LivePatch update system, and the company assures that there is no known exploitation of this vulnerability so far.

Identified as CVE-2026-91843, the flaw is rated 9.8 out of 10 on the CVSS scale, indicating its critical nature. The issue is due to a stack overflow during the login process, triggered by an overly long username in login requests, as noted by internet scanning company Censys.

Patch and Mitigation Measures

Check Point has advised that customers with automatic updates are already protected, while others should promptly apply the LivePatch fix as outlined in advisory sk1000155. The importance of this action is underscored by the potential impact of the flaw. As of now, U.S. Cybersecurity and Infrastructure Security Agency (CISA) reports no known exploitation.

Administrators are urged to confirm the installation of the patch by using the cplp list command to verify LivePatch statuses. Furthermore, it is crucial to ensure that Trusted Clients settings are restricted to known hosts, preventing unauthorized Internet access to management systems.

Affected Systems and Recommendations

The vulnerability impacts several Check Point branches, including R82.10 with Jumbo Hotfix Take 44 or below, and others as specified. Notably, R82.20 is also vulnerable, lacking a protective Jumbo Hotfix at present, as per Censys.

Standalone deployments, Log Servers, and Multi-Domain servers are equally affected, although the Smart-1 Cloud service remains secure with the fix already applied. Check Point assures that even out-of-support versions can receive fixes upon request.

Administrators should diligently apply the necessary patches and verify client access settings to mitigate potential risks. Despite no current exploitation, the severity of the flaw necessitates immediate action to safeguard systems.

As the fifth significant management flaw since July, vigilance remains crucial in protecting against potential threats. Check Point continues to monitor the situation closely, providing necessary updates and support to its customers.

The Hacker News Tags:Check Point, CIS security, code execution, CVE-2026-91843, cyber threat, Cybersecurity, network security, security flaw, security management, security update, server management, SmartConsole, system protection, unauthorized access, vulnerability patch

Post navigation

Previous Post: APT36’s USB Malware Threatens Secure Networks
Next Post: New Steam Vulnerability Allows Privilege Escalation

Related Posts

ZeroDayRAT Spyware Threatens Android and iOS Security ZeroDayRAT Spyware Threatens Android and iOS Security The Hacker News
Microsoft Begins NTLM Phase-Out With Three-Stage Plan to Move Windows to Kerberos Microsoft Begins NTLM Phase-Out With Three-Stage Plan to Move Windows to Kerberos The Hacker News
FortiBleed Credential Theft Ties Ransomware to INC and Lynx FortiBleed Credential Theft Ties Ransomware to INC and Lynx The Hacker News
U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware The Hacker News
Zoom Annotation Flaw Risks Meeting Participant Security Zoom Annotation Flaw Risks Meeting Participant Security The Hacker News
Critical cPanel Flaw Allows SQL Execution as Root Critical cPanel Flaw Allows SQL Execution as Root The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaws in BIND DNS Servers Threaten Security
  • Orkes Conductor Flaw Exploited in Recent Cyber Attacks
  • Iran-Affiliated Hackers Exploit Telegram for Data Breaches
  • FBI Shuts Down Major DDoS-for-Hire Platform NightmareStresser
  • MIND’s $72M Boost for AI-Enhanced Data Protection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaws in BIND DNS Servers Threaten Security
  • Orkes Conductor Flaw Exploited in Recent Cyber Attacks
  • Iran-Affiliated Hackers Exploit Telegram for Data Breaches
  • FBI Shuts Down Major DDoS-for-Hire Platform NightmareStresser
  • MIND’s $72M Boost for AI-Enhanced Data Protection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark