Daily Top · Network / Control Plane

Check Point management is unauthenticated root. LivePatch Take 24 is last week’s VPN. Take 28 is this login.

CVE-2026-91843 is a pre-auth stack overflow on Security Management and Log Servers. Vendor reports no exploitation. R82.20 is in scope. Trusted Clients set to Any is the same door as July.

RWP Ventures · 2026-09-18 · event 2026-09-16 · 12 min read · priority 8.3

Bottom line up front

CONFIRMED Check Point disclosed CVE-2026-91843 on 16 September 2026. CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). CWE-121. A stack overflow in the unauthenticated login process on Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server may let a remote attacker run code as root. Smart-1 Cloud is not affected. The vendor hunt string is a failed administrator login whose username is too long. The LivePatch that arms this CVE is Take 28 on R81.20 / R82 / R82.10 and Take 29 on R82.20. cplp list should show fwm:fwm armed for CVE-2026-91843.

This is not [last week’s VPN pair](/posts/2026-09-13-checkpoint-vpn-cve-2026-85102-85103/). CVE-2026-85102 / CVE-2026-85103 were certificate bugs. LivePatch Take 24 and Jumbo Take 44 / 126 / 166 closed those. They do not close this. R82.20 was out of 85102/85103. It is in 91843.

Check Point, in the 16 September CheckMates notice and in a 18 September reply to The Hacker News, says it has no indication of in-the-wild exploitation. CISA’s ADP on the CVE record on 17 September recorded exploitation as none. Catalog version 2026.09.16 (released 16 September 18:47 UTC, count 1713) does not list 91843. Treat this as a patch-now management-plane overflow, not as a confirmed compromise and not as KEV.

What happened

Check Point published sk1000155 on 16 September (last modified the same day) and opened a CheckMates advisory the same morning. CVE.org matches the SK: stack overflow during the unauthenticated login process, remote root. NHS England Digital listed a national alert for the SK on 17 September 02:27. The Hacker News carried English analysis on 17 September and updated it on 18 September with on-record answers from Aviv Abramovich, Check Point’s VP of product management for network security. Heise and SecurityWeek followed on the 18th.

Affected, from the SK: R82.20 (every build named there); R82.10 at Jumbo Hotfix Take 44 or lower; R82 at Take 126 or lower; R81.20 at Take 166 or lower; EoS R81.10 at Take 190 or lower; EoS R80 through R80.40 and R81. The CVE product-status block does not name R82.20. The SK does. Abramovich told The Hacker News that R82.20 is vulnerable, and that standalone (management plus gateway on one box), Log Servers, and Multi-Domain servers are in scope. Censys, citing the SK, said no Jumbo yet protects R82.20. That conflict is operational, not academic: an inventory that trusted only the CVE record would skip R82.20.

The fix is LivePatch, not a new Jumbo floor. Offline bundles in the SK: R82.20 BUNDLE_URGENT_SECURITY_UPDATE_R82_10_AUTOUPDATE take 29; R82.10 same bundle take 28; R82 BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE take 28; R81.20 BUNDLE_URGENT_SECURITY_UPDATE_R81_20_AUTOUPDATE take 28. Automatic-update customers under sk175504 are supposed to receive it; Check Point’s own community history from last week is that staged LivePatch rollout is not the same as “armed on every box the morning of the SK.” Validate with cplp list. Expected row: fwm:fwm armed livepatch CVE-2026-91843. A CheckMates staff reply said the impacted process is FWM, used for authentication.

Mitigation, not a fix: limit Trusted Clients (GUI clients) to known IPs. Do not leave Client Type as Any. Abramovich told The Hacker News the vulnerable path runs only through Trusted Clients. That is the same control that was the first mitigation for CVE-2026-16232 in July, when Check Point and CISA treated a SmartConsole authentication bypass as exploited against a handful of customers whose management was on the internet with no IP restrictions. 16232 is background. It is not evidence that 91843 is already in a kit.

Censys counted 3,836 hosts worldwide that present the default identity Check Point gives management and log servers. Censys’ own sentence: total role presence, not a confirmed-vulnerable count. Build and hotfix are not in the scan data. No public PoC as of 16 September, per Censys.

Why it matters

Three facts should not be collapsed.

First: this is unauthenticated root on the policy plane, not a VPN certificate bug and not a gateway-only issue. Security Management is the system that pushes firewall policy and holds administrator access. A root shell there is not “another Check Point CVE.” It is control of the estate the gateways enforce. Log Servers are in the same SK. Do not inventory only the SMS.

Second: last week’s patch math does not transfer. Operators who installed LivePatch Take 24, or Jumbo Take 44 / 126 / 166, closed 85102/85103. The 91843 affected set includes R82.10 Take 44, R82 Take 126, and R81.20 Take 166. Those Jumbo takes are the VPN fix and still inside this overflow’s affected window. R82.20 owners who correctly sat out last week because the VPN SKs said they were not affected are in this SK. Take 24 is not Take 28. Take 28 is not Take 29.

Third: the vendor “no exploitation” line is the current evidence. It is not a reason to leave Trusted Clients on Any. July’s 16232 was exploited in exactly that configuration. CISA has not listed 91843. We will not invent a Qilin campaign, a TAC-found victim, or a KEV clock. We will also not wait for one. NCSC-NL’s “imminent” language last week was about 85102/85103, not this CVE.

We have no confirmed OT, ICS, or physical-process impact. A Check Point management server in front of a plant is still an IT compromise of an industrial organization’s policy plane. Do not write a process event.

Who / what is affected

AssetWhat to assumeStatus
Security Management, MDS, Log Server, Multi-Domain Log ServerUnauthenticated root via login-process stack overflowCONFIRMED SK
R82.20Affected; LivePatch take 29; no Jumbo named as a closeCONFIRMED SK; CONFIRMED Abramovich to THN; CVE record omits the branch
R82.10 Take 44 or lower; R82 Take 126 or lower; R81.20 Take 166 or lowerAffectedCONFIRMED SK
EoS R80–R81.10Affected; SK has no LivePatch row; Abramovich: EoS fix via a support ticketCONFIRMED SK; REPORTED vendor to THN
Smart-1 CloudNot affected; fix already in placeCONFIRMED SK; NHS England Digital citing SK
Standalone (gateway + management)In scopeCONFIRMED Abramovich to THN
LivePatch Take 24 / Jumbo that closed 85102/85103Not the 91843 closeCONFIRMED by comparing SK take numbers
Trusted Clients = Any, management reachablePractical exposureCONFIRMED as vendor mitigation path; ASSESSED as the July 16232 overlap
CISA KEVNot listed as of 2026.09.16CONFIRMED absent
In-the-wild exploitationNone reportedCONFIRMED vendor; CISA ADP “none” 17 Sep
OT / PLC / processNot claimedNo evidence

Technical context

RWP is not reproducing login payloads, username lengths, or FWM crash input. Check Point’s public description is enough for a defender: the overflow is in the login path before authentication completes; Censys describes the trigger as a login request with an excessively long username; the SK hunt is the resulting audit line; the LivePatch lands on fwm.

ATT&CK mapping for what is stated by the CVE and SK, not a hypothetical kill chain:

Follow-on that is not claimed here: named C2, a named ransomware brand, identity of 91843 with 85102/85103 or with 16232, or a public exploit.

Threat / exploitation status

ClaimStatusBasis
CVE-2026-91843 is CVSS 9.8 unauthenticated stack overflow to rootCONFIRMEDCheck Point SK; CVE.org
Products: SMS, MDS, Log Server, Multi-Domain Log ServerCONFIRMEDSK
Smart-1 Cloud not affectedCONFIRMEDSK
R82.20 affectedCONFIRMED SK / vendor to THN; UNKNOWN in the CVE product-status blockTreat SK as the operator source
LivePatch Take 28 / 29; fwm:fwm armedCONFIRMEDSK
Hunt: “Administrator failed to log in: Username too long”CONFIRMEDSK; Heise
In-the-wild exploitationNONE reportedVendor CheckMates; Abramovich to THN; CISA ADP 17 Sep
Public PoCNONE reported as of 16 SepCensys
CISA KEVNot listedCatalog 2026.09.16
Named actor / family / victimUNKNOWNUnpublished
OT / physical-process impactNot claimedNo evidence

High confidence on: CVE identifier, CVSS, product list, LivePatch take numbers, hunt string, Smart-1 Cloud exclusion, distinctness from 85102/85103, absence from KEV 2026.09.16. Moderate confidence that Trusted Clients = Any plus a reachable management IP is the practical target set (vendor path statement; no census of that misconfiguration). Low confidence on finder, current internet-reachable vulnerable-build count, and whether a staged LivePatch has actually armed every automatic-update customer.

What defenders should do

  1. Inventory every Security Management, MDS, Log Server, Multi-Domain Log Server, and standalone — production, lab, DR, the box that still answers on the old IP. Record version, Jumbo take, LivePatch take, whether Trusted Clients is Any, and whether the management IP is reachable from a network that is not the admin VLAN. Include plant-perimeter management. R82.20: document it. Do not skip it because last week’s VPN SKs said it was clean.
  1. Hunt the SK string before you close the ticket. In SmartConsole, Audit and Admin login logs: Administrator failed to log in: Username too long. A hit is a reason to treat the box as hostile, not as a failed-login curiosity. Preserve logs and snapshots before you replace the VM.
  1. Arm LivePatch Take 28 (R81.20 / R82 / R82.10) or Take 29 (R82.20). Confirm with cplp list. If automatic updates are on, do not assume the SK’s “already protected” sentence. Last week’s Take 24 rollout lagged on some CheckMates systems the day of that advisory. EoS R80–R81.10: open a Check Point support ticket for the EoS package Abramovich described, or migrate.
  1. Restrict Trusted Clients now, whether or not the LivePatch is armed. Known IPs. Not Any. Do not expose management to the internet. That is the SK mitigation and the same control that was the difference between “vulnerable” and “exploited” for 16232 in July.
  1. Sequence the rest of this week’s clock. [Cisco ISE CVE-2026-76460](/posts/2026-09-17-cisco-ise-cve-2026-76460-auth-bypass/) is KEV-due 19 September, forensic triage Yes. Pixel CVE-2026-58704 and Acronis CVE-2026-87886 share that due date. Chromium V8 CVE-2026-85046 is KEV-due today, 18 September. [Cisco SEG CVE-2026-76461](/posts/2026-09-15-cisco-seg-cve-2026-76461-sqli/) was due 17 September. [vCenter CVE-2026-59310](/posts/2026-09-16-vmware-vcenter-cve-2026-59310-ransomware/) is ransomware-Known. Artifactory CVE-2026-42016 / 42018 due 25 September. 91843 is not on that federal list. It is still today’s management-plane overflow.

This is not an exploitation guide. Use Check Point’s SK and the audit log.

RWP assessment

Score 8.3. Unauthenticated CVSS 9.8 root on the firewall policy plane, configuration path through Trusted Clients, R82.20 newly in scope, LivePatch take numbers that do not match last week’s VPN close. English coverage and the vendor on-record confirmation of R82.20 / standalone / Log Server landed 18 September, after [yesterday’s ISE Daily Top](/posts/2026-09-17-cisco-ise-cve-2026-76460-auth-bypass/). RWP has not published 91843 as a Daily Top.

It is not a re-run of [85102/85103](/posts/2026-09-13-checkpoint-vpn-cve-2026-85102-85103/). Different CWE, different process (FWM vs certificate/IKE), different LivePatch take, opposite R82.20 status. It outranks Orkes Conductor CVE-2026-58138 (SecurityWeek 18 September: unauthenticated GraalVM RCE, patched in June, PoC in August, Fortinet outbreak alert this week — real exploitation, narrower enterprise-control-plane relevance, not KEV). It outranks the Revolut impersonation-and-ransom reporting (legal-request fraud against ~680 customers; not a product CVE). It outranks the 17 September CISA ICS batch (Schneider, ABB, Hitachi Energy, Mitsubishi, Bransys — no exploitation claimed; weekly OT material). It outranks Chromium 85046 as a story: that KEV clock expires today, but the addition was 4 September. ISE 76460, SEG 76461, and vCenter 59310 are continuations of this week’s already-published tops.

The failure mode to sand down is “we patched Check Point last week.” You patched VPN certificates. You have not necessarily patched FWM. If Trusted Clients is still Any, you are standing in the same doorway Check Point already watched get walked through in July.

What we are watching

Sources

Sources

  1. Check Point — sk1000155 CVE-2026-91843
  2. CVE — CVE-2026-91843
  3. Check Point CheckMates — Critical Security Update CVE-2026-91843
  4. The Hacker News — Critical Check Point Management Flaw
  5. Censys — CVE-2026-91843 advisory
  6. heise online — Root security flaw in Check Point Security Management
  7. SecurityWeek — Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
  8. NHS England Digital — Cyber alerts listing CVE-2026-91843
  9. CISA — KEV JSON feed catalog 2026.09.16
  10. CISA — Known Exploited Vulnerabilities Catalog
  11. Check Point — LivePatch sk185114
  12. Check Point — Automatic updates sk175504