Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaw in Check Point Servers Enables Code Execution

Critical Flaw in Check Point Servers Enables Code Execution

Posted on September 18, 2026 By CWS

A significant vulnerability has been identified in Check Point’s Security Management and Log Servers, which could permit attackers to execute code as root without needing login credentials. This flaw, present in the servers’ network operations, poses a critical security risk.

Details of the Vulnerability

The flaw resides within the Security Management Server, which oversees firewall policies and administrator access. According to Check Point, the vulnerability is linked to the Trusted Clients setting within the SmartConsole, which manages connections to the management server. A patch has been issued via Check Point’s LivePatch update system, and the company assures that there is no known exploitation of this vulnerability so far.

Identified as CVE-2026-91843, the flaw is rated 9.8 out of 10 on the CVSS scale, indicating its critical nature. The issue is due to a stack overflow during the login process, triggered by an overly long username in login requests, as noted by internet scanning company Censys.

Patch and Mitigation Measures

Check Point has advised that customers with automatic updates are already protected, while others should promptly apply the LivePatch fix as outlined in advisory sk1000155. The importance of this action is underscored by the potential impact of the flaw. As of now, U.S. Cybersecurity and Infrastructure Security Agency (CISA) reports no known exploitation.

Administrators are urged to confirm the installation of the patch by using the cplp list command to verify LivePatch statuses. Furthermore, it is crucial to ensure that Trusted Clients settings are restricted to known hosts, preventing unauthorized Internet access to management systems.

Affected Systems and Recommendations

The vulnerability impacts several Check Point branches, including R82.10 with Jumbo Hotfix Take 44 or below, and others as specified. Notably, R82.20 is also vulnerable, lacking a protective Jumbo Hotfix at present, as per Censys.

Standalone deployments, Log Servers, and Multi-Domain servers are equally affected, although the Smart-1 Cloud service remains secure with the fix already applied. Check Point assures that even out-of-support versions can receive fixes upon request.

Administrators should diligently apply the necessary patches and verify client access settings to mitigate potential risks. Despite no current exploitation, the severity of the flaw necessitates immediate action to safeguard systems.

As the fifth significant management flaw since July, vigilance remains crucial in protecting against potential threats. Check Point continues to monitor the situation closely, providing necessary updates and support to its customers.

The Hacker News Tags:Check Point, CIS security, code execution, CVE-2026-91843, cyber threat, Cybersecurity, network security, security flaw, security management, security update, server management, SmartConsole, system protection, unauthorized access, vulnerability patch

Post navigation

Previous Post: APT36’s USB Malware Threatens Secure Networks
Next Post: New Steam Vulnerability Allows Privilege Escalation

Related Posts

Helping CISOs Speak the Language of Business Helping CISOs Speak the Language of Business The Hacker News
Exploring Vulnerable Drivers Without Hardware Exploring Vulnerable Drivers Without Hardware The Hacker News
How to Protect the Invisible Identity Access How to Protect the Invisible Identity Access The Hacker News
ValleyRAT Malware Concealed in Trusted Adware ValleyRAT Malware Concealed in Trusted Adware The Hacker News
Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild The Hacker News
Canada’s Spy Agency Neutralizes Botnets with Unique Warrant Canada’s Spy Agency Neutralizes Botnets with Unique Warrant The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • FBI Shuts Down Major DDoS-for-Hire Platform NightmareStresser
  • MIND’s $72M Boost for AI-Enhanced Data Protection
  • Critical Docker Flaw on macOS Exposes Host Files
  • OpenAI Reveals Security Breaches in AI Model Operations
  • RatHat Malware Exploits ADB for Persistent Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • FBI Shuts Down Major DDoS-for-Hire Platform NightmareStresser
  • MIND’s $72M Boost for AI-Enhanced Data Protection
  • Critical Docker Flaw on macOS Exposes Host Files
  • OpenAI Reveals Security Breaches in AI Model Operations
  • RatHat Malware Exploits ADB for Persistent Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark