Check Point management is unauthenticated root. LivePatch Take 24 is last week’s VPN. Take 28 is this login.
CVE-2026-91843 is a pre-auth stack overflow on Security Management and Log Servers. Vendor reports no exploitation. R82.20 is in scope. Trusted Clients set to Any is the same door as July.
Bottom line up front
CONFIRMED Check Point disclosed CVE-2026-91843 on 16 September 2026. CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). CWE-121. A stack overflow in the unauthenticated login process on Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server may let a remote attacker run code as root. Smart-1 Cloud is not affected. The vendor hunt string is a failed administrator login whose username is too long. The LivePatch that arms this CVE is Take 28 on R81.20 / R82 / R82.10 and Take 29 on R82.20. cplp list should show fwm:fwm armed for CVE-2026-91843.
This is not [last week’s VPN pair](/posts/2026-09-13-checkpoint-vpn-cve-2026-85102-85103/). CVE-2026-85102 / CVE-2026-85103 were certificate bugs. LivePatch Take 24 and Jumbo Take 44 / 126 / 166 closed those. They do not close this. R82.20 was out of 85102/85103. It is in 91843.
Check Point, in the 16 September CheckMates notice and in a 18 September reply to The Hacker News, says it has no indication of in-the-wild exploitation. CISA’s ADP on the CVE record on 17 September recorded exploitation as none. Catalog version 2026.09.16 (released 16 September 18:47 UTC, count 1713) does not list 91843. Treat this as a patch-now management-plane overflow, not as a confirmed compromise and not as KEV.
What happened
Check Point published sk1000155 on 16 September (last modified the same day) and opened a CheckMates advisory the same morning. CVE.org matches the SK: stack overflow during the unauthenticated login process, remote root. NHS England Digital listed a national alert for the SK on 17 September 02:27. The Hacker News carried English analysis on 17 September and updated it on 18 September with on-record answers from Aviv Abramovich, Check Point’s VP of product management for network security. Heise and SecurityWeek followed on the 18th.
Affected, from the SK: R82.20 (every build named there); R82.10 at Jumbo Hotfix Take 44 or lower; R82 at Take 126 or lower; R81.20 at Take 166 or lower; EoS R81.10 at Take 190 or lower; EoS R80 through R80.40 and R81. The CVE product-status block does not name R82.20. The SK does. Abramovich told The Hacker News that R82.20 is vulnerable, and that standalone (management plus gateway on one box), Log Servers, and Multi-Domain servers are in scope. Censys, citing the SK, said no Jumbo yet protects R82.20. That conflict is operational, not academic: an inventory that trusted only the CVE record would skip R82.20.
The fix is LivePatch, not a new Jumbo floor. Offline bundles in the SK: R82.20 BUNDLE_URGENT_SECURITY_UPDATE_R82_10_AUTOUPDATE take 29; R82.10 same bundle take 28; R82 BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE take 28; R81.20 BUNDLE_URGENT_SECURITY_UPDATE_R81_20_AUTOUPDATE take 28. Automatic-update customers under sk175504 are supposed to receive it; Check Point’s own community history from last week is that staged LivePatch rollout is not the same as “armed on every box the morning of the SK.” Validate with cplp list. Expected row: fwm:fwm armed livepatch CVE-2026-91843. A CheckMates staff reply said the impacted process is FWM, used for authentication.
Mitigation, not a fix: limit Trusted Clients (GUI clients) to known IPs. Do not leave Client Type as Any. Abramovich told The Hacker News the vulnerable path runs only through Trusted Clients. That is the same control that was the first mitigation for CVE-2026-16232 in July, when Check Point and CISA treated a SmartConsole authentication bypass as exploited against a handful of customers whose management was on the internet with no IP restrictions. 16232 is background. It is not evidence that 91843 is already in a kit.
Censys counted 3,836 hosts worldwide that present the default identity Check Point gives management and log servers. Censys’ own sentence: total role presence, not a confirmed-vulnerable count. Build and hotfix are not in the scan data. No public PoC as of 16 September, per Censys.
Why it matters
Three facts should not be collapsed.
First: this is unauthenticated root on the policy plane, not a VPN certificate bug and not a gateway-only issue. Security Management is the system that pushes firewall policy and holds administrator access. A root shell there is not “another Check Point CVE.” It is control of the estate the gateways enforce. Log Servers are in the same SK. Do not inventory only the SMS.
Second: last week’s patch math does not transfer. Operators who installed LivePatch Take 24, or Jumbo Take 44 / 126 / 166, closed 85102/85103. The 91843 affected set includes R82.10 Take 44, R82 Take 126, and R81.20 Take 166. Those Jumbo takes are the VPN fix and still inside this overflow’s affected window. R82.20 owners who correctly sat out last week because the VPN SKs said they were not affected are in this SK. Take 24 is not Take 28. Take 28 is not Take 29.
Third: the vendor “no exploitation” line is the current evidence. It is not a reason to leave Trusted Clients on Any. July’s 16232 was exploited in exactly that configuration. CISA has not listed 91843. We will not invent a Qilin campaign, a TAC-found victim, or a KEV clock. We will also not wait for one. NCSC-NL’s “imminent” language last week was about 85102/85103, not this CVE.
We have no confirmed OT, ICS, or physical-process impact. A Check Point management server in front of a plant is still an IT compromise of an industrial organization’s policy plane. Do not write a process event.
Who / what is affected
| Asset | What to assume | Status |
|---|---|---|
| Security Management, MDS, Log Server, Multi-Domain Log Server | Unauthenticated root via login-process stack overflow | CONFIRMED SK |
| R82.20 | Affected; LivePatch take 29; no Jumbo named as a close | CONFIRMED SK; CONFIRMED Abramovich to THN; CVE record omits the branch |
| R82.10 Take 44 or lower; R82 Take 126 or lower; R81.20 Take 166 or lower | Affected | CONFIRMED SK |
| EoS R80–R81.10 | Affected; SK has no LivePatch row; Abramovich: EoS fix via a support ticket | CONFIRMED SK; REPORTED vendor to THN |
| Smart-1 Cloud | Not affected; fix already in place | CONFIRMED SK; NHS England Digital citing SK |
| Standalone (gateway + management) | In scope | CONFIRMED Abramovich to THN |
| LivePatch Take 24 / Jumbo that closed 85102/85103 | Not the 91843 close | CONFIRMED by comparing SK take numbers |
| Trusted Clients = Any, management reachable | Practical exposure | CONFIRMED as vendor mitigation path; ASSESSED as the July 16232 overlap |
| CISA KEV | Not listed as of 2026.09.16 | CONFIRMED absent |
| In-the-wild exploitation | None reported | CONFIRMED vendor; CISA ADP “none” 17 Sep |
| OT / PLC / process | Not claimed | No evidence |
Technical context
RWP is not reproducing login payloads, username lengths, or FWM crash input. Check Point’s public description is enough for a defender: the overflow is in the login path before authentication completes; Censys describes the trigger as a login request with an excessively long username; the SK hunt is the resulting audit line; the LivePatch lands on fwm.
ATT&CK mapping for what is stated by the CVE and SK, not a hypothetical kill chain:
- Initial access: exploit public-facing application on management/log login (T1190), if a Trusted Client path exists to FWM.
- Execution: command execution as root (T1059), stated as the overflow outcome.
- Impact on the estate: a compromised SMS can change policy. That follow-on is why the box matters. It is not a second CVE.
Follow-on that is not claimed here: named C2, a named ransomware brand, identity of 91843 with 85102/85103 or with 16232, or a public exploit.
Threat / exploitation status
| Claim | Status | Basis |
|---|---|---|
| CVE-2026-91843 is CVSS 9.8 unauthenticated stack overflow to root | CONFIRMED | Check Point SK; CVE.org |
| Products: SMS, MDS, Log Server, Multi-Domain Log Server | CONFIRMED | SK |
| Smart-1 Cloud not affected | CONFIRMED | SK |
| R82.20 affected | CONFIRMED SK / vendor to THN; UNKNOWN in the CVE product-status block | Treat SK as the operator source |
LivePatch Take 28 / 29; fwm:fwm armed | CONFIRMED | SK |
| Hunt: “Administrator failed to log in: Username too long” | CONFIRMED | SK; Heise |
| In-the-wild exploitation | NONE reported | Vendor CheckMates; Abramovich to THN; CISA ADP 17 Sep |
| Public PoC | NONE reported as of 16 Sep | Censys |
| CISA KEV | Not listed | Catalog 2026.09.16 |
| Named actor / family / victim | UNKNOWN | Unpublished |
| OT / physical-process impact | Not claimed | No evidence |
High confidence on: CVE identifier, CVSS, product list, LivePatch take numbers, hunt string, Smart-1 Cloud exclusion, distinctness from 85102/85103, absence from KEV 2026.09.16. Moderate confidence that Trusted Clients = Any plus a reachable management IP is the practical target set (vendor path statement; no census of that misconfiguration). Low confidence on finder, current internet-reachable vulnerable-build count, and whether a staged LivePatch has actually armed every automatic-update customer.
What defenders should do
- Inventory every Security Management, MDS, Log Server, Multi-Domain Log Server, and standalone — production, lab, DR, the box that still answers on the old IP. Record version, Jumbo take, LivePatch take, whether Trusted Clients is Any, and whether the management IP is reachable from a network that is not the admin VLAN. Include plant-perimeter management. R82.20: document it. Do not skip it because last week’s VPN SKs said it was clean.
- Hunt the SK string before you close the ticket. In SmartConsole, Audit and Admin login logs:
Administrator failed to log in: Username too long. A hit is a reason to treat the box as hostile, not as a failed-login curiosity. Preserve logs and snapshots before you replace the VM.
- Arm LivePatch Take 28 (R81.20 / R82 / R82.10) or Take 29 (R82.20). Confirm with
cplp list. If automatic updates are on, do not assume the SK’s “already protected” sentence. Last week’s Take 24 rollout lagged on some CheckMates systems the day of that advisory. EoS R80–R81.10: open a Check Point support ticket for the EoS package Abramovich described, or migrate.
- Restrict Trusted Clients now, whether or not the LivePatch is armed. Known IPs. Not Any. Do not expose management to the internet. That is the SK mitigation and the same control that was the difference between “vulnerable” and “exploited” for 16232 in July.
- Sequence the rest of this week’s clock. [Cisco ISE CVE-2026-76460](/posts/2026-09-17-cisco-ise-cve-2026-76460-auth-bypass/) is KEV-due 19 September, forensic triage Yes. Pixel CVE-2026-58704 and Acronis CVE-2026-87886 share that due date. Chromium V8 CVE-2026-85046 is KEV-due today, 18 September. [Cisco SEG CVE-2026-76461](/posts/2026-09-15-cisco-seg-cve-2026-76461-sqli/) was due 17 September. [vCenter CVE-2026-59310](/posts/2026-09-16-vmware-vcenter-cve-2026-59310-ransomware/) is ransomware-Known. Artifactory CVE-2026-42016 / 42018 due 25 September. 91843 is not on that federal list. It is still today’s management-plane overflow.
This is not an exploitation guide. Use Check Point’s SK and the audit log.
RWP assessment
Score 8.3. Unauthenticated CVSS 9.8 root on the firewall policy plane, configuration path through Trusted Clients, R82.20 newly in scope, LivePatch take numbers that do not match last week’s VPN close. English coverage and the vendor on-record confirmation of R82.20 / standalone / Log Server landed 18 September, after [yesterday’s ISE Daily Top](/posts/2026-09-17-cisco-ise-cve-2026-76460-auth-bypass/). RWP has not published 91843 as a Daily Top.
It is not a re-run of [85102/85103](/posts/2026-09-13-checkpoint-vpn-cve-2026-85102-85103/). Different CWE, different process (FWM vs certificate/IKE), different LivePatch take, opposite R82.20 status. It outranks Orkes Conductor CVE-2026-58138 (SecurityWeek 18 September: unauthenticated GraalVM RCE, patched in June, PoC in August, Fortinet outbreak alert this week — real exploitation, narrower enterprise-control-plane relevance, not KEV). It outranks the Revolut impersonation-and-ransom reporting (legal-request fraud against ~680 customers; not a product CVE). It outranks the 17 September CISA ICS batch (Schneider, ABB, Hitachi Energy, Mitsubishi, Bransys — no exploitation claimed; weekly OT material). It outranks Chromium 85046 as a story: that KEV clock expires today, but the addition was 4 September. ISE 76460, SEG 76461, and vCenter 59310 are continuations of this week’s already-published tops.
The failure mode to sand down is “we patched Check Point last week.” You patched VPN certificates. You have not necessarily patched FWM. If Trusted Clients is still Any, you are standing in the same doorway Check Point already watched get walked through in July.
What we are watching
- Whether CISA lists 91843, flips ADP exploitation off “none,” or a national CERT publishes more than the SK hunt string.
- Whether LivePatch Take 28/29 actually arms, or staged rollout repeats last week’s Take 24 lag.
- R82.20 owners who sat out 85102/85103.
- Any public PoC, or a Trusted Clients = Any victim.
- ISE 76460, Pixel 58704, and Acronis 87886 through 19 September.
- Any attempt to treat a Check Point management compromise at an industrial tenant as an OT event without process evidence.
Sources
- Check Point — sk1000155 (CVE-2026-91843)
- CVE.org — CVE-2026-91843
- Check Point CheckMates — Critical Security Update CVE-2026-91843 (16 September 2026)
- The Hacker News — Critical Check Point Management Flaw (17 September 2026, updated 18 September)
- Censys — CVE-2026-91843 advisory (16 September 2026)
- heise online — Root security flaw in Check Point Security Management (18 September 2026)
- SecurityWeek — Check Point, Kaspersky, Tanium Patch Product Vulnerabilities (18 September 2026)
- NHS England Digital — Cyber alerts
- CISA KEV JSON feed
- CISA Known Exploited Vulnerabilities Catalog
- Check Point — LivePatch sk185114
- Check Point — Automatic updates sk175504
- [RWP Daily Top, 17 September 2026 — Cisco ISE CVE-2026-76460](/posts/2026-09-17-cisco-ise-cve-2026-76460-auth-bypass/)
- [RWP Daily Top, 13 September 2026 — Check Point CVE-2026-85102 / 85103](/posts/2026-09-13-checkpoint-vpn-cve-2026-85102-85103/)
- [RWP Daily Top, 16 September 2026 — vCenter CVE-2026-59310](/posts/2026-09-16-vmware-vcenter-cve-2026-59310-ransomware/)
- [RWP Daily Top, 15 September 2026 — Cisco SEG CVE-2026-76461](/posts/2026-09-15-cisco-seg-cve-2026-76461-sqli/)
Sources
- Check Point — sk1000155 CVE-2026-91843
- CVE — CVE-2026-91843
- Check Point CheckMates — Critical Security Update CVE-2026-91843
- The Hacker News — Critical Check Point Management Flaw
- Censys — CVE-2026-91843 advisory
- heise online — Root security flaw in Check Point Security Management
- SecurityWeek — Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
- NHS England Digital — Cyber alerts listing CVE-2026-91843
- CISA — KEV JSON feed catalog 2026.09.16
- CISA — Known Exploited Vulnerabilities Catalog
- Check Point — LivePatch sk185114
- Check Point — Automatic updates sk175504