Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: management-server (2 articles)Clear

Critical Check Point management flaw lets unauthenticated attackers gain root

Check Point patched a critical flaw in its management servers that lets an unauthenticated attacker run code as root. Tracked as CVE-2026-91843 and scored 9.8, it is a stack overflow in the login process, which handles requests before a user authenticates, and it can be triggered by a login request carrying an overly long username. It affects Quantum management, Log, and Multi-Domain servers, through the Trusted Clients path. Customers with automatic updates are already protected, and others should apply the vendor's live patch. Check Point reports no exploitation yet, but this is the third serious management-server flaw it has disclosed in weeks, and compromising it means control over the whole firewall estate.

Check
Apply Check Point's live patch for the management-server flaw now if automatic updates are not enabled, and restrict which clients can reach the management, Log, and Multi-Domain servers.
Affected
Organizations running affected Check Point Quantum management, Log, or Multi-Domain servers (CVE-2026-91843); an unauthenticated attacker can trigger a login overflow with a long username to run code as root.
Fix
Patch or confirm automatic updates applied, tightly restrict access to management-plane servers, monitor for anomalous pre-authentication login traffic, and treat the management plane as the highest-value target since it controls every firewall.

Check Point patches exploited SmartConsole flaw giving attackers full admin access

Check Point has fixed an actively exploited flaw in SmartConsole, the graphical admin panel used to manage its security products. CVE-2026-16232, rated 9.3, is an authentication bypass letting an unauthenticated remote attacker obtain a login token and authenticate with administrator privileges, after which they can alter security configuration and policy on a Security Management or Multi-Domain Management server. Exploitation requires the management server to be reachable from the internet with no restrictions on trusted GUI clients. The same update fixes a second critical authentication bypass and a Gaia Portal issue letting read-only users run commands as root.

Check
Install the July 22 Jumbo hotfix on Security Management and Multi-Domain Management servers, then restrict trusted GUI clients to approved addresses and firewall management access to known sources.
Affected
Organizations running Check Point Security Management or Multi-Domain Management with the console reachable from the internet (CVE-2026-16232); attackers gain administrator access and can rewrite the security policy protecting the network.
Fix
Apply the hotfix, limit trusted clients to specific addresses, keep management interfaces off the public internet, and review policy changes and administrator logins for unauthorized modifications.