INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Check Point Management Server Zero-Day Exploited by Hackers
| 2026-09-23 06:14 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The US cybersecurity agency CISA has added two critical-severity vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a zero-day bug in Check Point's Security Gateway and Spark Firewall products. The first vulnerability, CVE-2026-85102, is described as an improper validation of certificate data during VPN negotiation, allowing remote attackers to bypass authentication and execute arbitrary code on the Security Gateway. This vulnerability has been patched by Check Point since September 9. A second vulnerability, CVE-2026-93616, is a directory traversal and file upload issue that could allow unauthenticated attackers to upload and execute arbitrary scripts on the Management Server. Check Point released urgent patches for this vulnerability as well. These vulnerabilities highlight the importance of timely patching and proper security measures in preventing exploitation by malicious actors.
Technical Mitigations AI-generated
• Limit access to the Management Server behind a security gateway or a firewall.
• Limit access to port TCP/19009 to trusted IP addresses.
• Apply the R82.20 Security Hotfix (TAR) and include fixes in Jumbo Hotfix Accumulator for affected versions.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SparkSparkQilinQilin
CVE-2024-24919CVE-2024-24919
CVE-2026-18574CVE-2026-18574
CVE-2026-85102CVE-2026-85102
CVE-2026-91843CVE-2026-91843
CVE-2026-62144CVE-2026-62144
CVE-2026-85103CVE-2026-85103
CVE-2026-50751CVE-2026-50751
CVE-2026-93616CVE-2026-93616
CVE-2026-16232CVE-2026-16232
Target & Sectors
Global Scope
technologytechnology
Incident Timeline
at least 2007
The FBI and CISA have urged software companies to remove path traversal weaknesses from their products since at least 2007.
Click on any entity below to view its context and source!
attribution
FBI
The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have urged software companies since May 2024
to remove path traversal weaknesses
from their products before shipping, saying such security issues "have been called 'unforgivable' since at least 2007.
May 2024
The FBI and CISA urged software companies to remove path traversal weaknesses from their products since May 2024.
Click on any entity below to view its context and source!
attribution
FBI
The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have urged software companies since May 2024
to remove path traversal weaknesses
from their products before shipping, saying such security issues "have been called 'unforgivable' since at least 2007.
July 22
An attacker exploited the CVE-2026-91843 vulnerability in Check Point's Security Management Server without logging in, starting on July 22.
Click on any entity below to view its context and source!
tactic
T1584.004 - Server
By The Hacker News' count of Check Point's CVE records, CVE-2026-91843 is the fifth critical flaw since July 22 that an attacker could reach on the Security Management Server without logging in.
organisation
The Security Management
By The Hacker News' count of Check Point's CVE records, CVE-2026-91843 is the fifth critical flaw since July 22 that an attacker could reach on the Security Management Server without logging in.
vulnerability
CVE-2026-91843
By The Hacker News' count of Check Point's CVE records, CVE-2026-91843 is the fifth critical flaw since July 22 that an attacker could reach on the Security Management Server without logging in.
August 3
Threat actors exploited CVE-2026-18574, an authentication bypass vulnerability in Check Point's management server, on August 3.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-85103
Two more followed:
CVE-2026-18574
, an authentication bypass that could allow command execution on the management server, on August 3, and CVE-2026-85103, a heap overflow in VPN certificate decoding that also reaches Quantum Security Management, on September 9.
organisation
CVE-2026
Two more followed:
CVE-2026-18574
, an authentication bypass that could allow command execution on the management server, on August 3, and CVE-2026-85103, a heap overflow in VPN certificate decoding that also reaches Quantum Security Management, on September 9.
vulnerability
CVE-2026-18574
Two more followed:
CVE-2026-18574
, an authentication bypass that could allow command execution on the management server, on August 3, and CVE-2026-85103, a heap overflow in VPN certificate decoding that also reaches Quantum Security Management, on September 9.
organisation
Quantum Security Management
Two more followed:
CVE-2026-18574
, an authentication bypass that could allow command execution on the management server, on August 3, and CVE-2026-85103, a heap overflow in VPN certificate decoding that also reaches Quantum Security Management, on September 9.
September 9
Threat actors exploited a zero-day authentication bypass (CVE-2026-18574) and a heap overflow in VPN certificate decoding (CVE-2026-85103) to target Check Point's Security Gateway, Spark Firewall, and Quantum Security Management products.
Click on any entity below to view its context and source!
source_region
United States
On Tuesday, the US cybersecurity agency CISA added the zero-day bug to its Known Exploited Vulnerabilities (KEV) catalog alongside CVE-2026-85102 (CVSS score of 9.8), a security defect in Check Point’s Security Gateway and Spark Firewall products that
was patched
on September 9.
vulnerability
CVE-2026-85102
On Tuesday, the US cybersecurity agency CISA added the zero-day bug to its Known Exploited Vulnerabilities (KEV) catalog alongside CVE-2026-85102 (CVSS score of 9.8), a security defect in Check Point’s Security Gateway and Spark Firewall products that
was patched
on September 9.
vulnerability
CVSS score of 9.8
On Tuesday, the US cybersecurity agency CISA added the zero-day bug to its Known Exploited Vulnerabilities (KEV) catalog alongside CVE-2026-85102 (CVSS score of 9.8), a security defect in Check Point’s Security Gateway and Spark Firewall products that
was patched
on September 9.
attribution
CISA
On Tuesday, the US cybersecurity agency CISA added the zero-day bug to its Known Exploited Vulnerabilities (KEV) catalog alongside CVE-2026-85102 (CVSS score of 9.8), a security defect in Check Point’s Security Gateway and Spark Firewall products that
was patched
on September 9.
organisation
Known Exploited
On Tuesday, the US cybersecurity agency CISA added the zero-day bug to its Known Exploited Vulnerabilities (KEV) catalog alongside CVE-2026-85102 (CVSS score of 9.8), a security defect in Check Point’s Security Gateway and Spark Firewall products that
was patched
on September 9.
tactic
T1588.006 - Vulnerabilities
On Tuesday, the US cybersecurity agency CISA added the zero-day bug to its Known Exploited Vulnerabilities (KEV) catalog alongside CVE-2026-85102 (CVSS score of 9.8), a security defect in Check Point’s Security Gateway and Spark Firewall products that
was patched
on September 9.
organisation
KEV
On Tuesday, the US cybersecurity agency CISA added the zero-day bug to its Known Exploited Vulnerabilities (KEV) catalog alongside CVE-2026-85102 (CVSS score of 9.8), a security defect in Check Point’s Security Gateway and Spark Firewall products that
was patched
on September 9.
organisation
Check Point’s Security Gateway
On Tuesday, the US cybersecurity agency CISA added the zero-day bug to its Known Exploited Vulnerabilities (KEV) catalog alongside CVE-2026-85102 (CVSS score of 9.8), a security defect in Check Point’s Security Gateway and Spark Firewall products that
was patched
on September 9.
malware
Spark
On Tuesday, the US cybersecurity agency CISA added the zero-day bug to its Known Exploited Vulnerabilities (KEV) catalog alongside CVE-2026-85102 (CVSS score of 9.8), a security defect in Check Point’s Security Gateway and Spark Firewall products that
was patched
on September 9.
vulnerability
CVE-2026-85103
Two more followed:
CVE-2026-18574
, an authentication bypass that could allow command execution on the management server, on August 3, and CVE-2026-85103, a heap overflow in VPN certificate decoding that also reaches Quantum Security Management, on September 9.
organisation
CVE-2026
Two more followed:
CVE-2026-18574
, an authentication bypass that could allow command execution on the management server, on August 3, and CVE-2026-85103, a heap overflow in VPN certificate decoding that also reaches Quantum Security Management, on September 9.
vulnerability
CVE-2026-18574
Two more followed:
CVE-2026-18574
, an authentication bypass that could allow command execution on the management server, on August 3, and CVE-2026-85103, a heap overflow in VPN certificate decoding that also reaches Quantum Security Management, on September 9.
organisation
Quantum Security Management
Two more followed:
CVE-2026-18574
, an authentication bypass that could allow command execution on the management server, on August 3, and CVE-2026-85103, a heap overflow in VPN certificate decoding that also reaches Quantum Security Management, on September 9.
September 9, 2026
Threat actors exploited a zero-day vulnerability in Check Point's management server, which was disclosed and patched by the vendor on September 9, 2026.
2026/09/10
Threat actors exploited a zero-day vulnerability in Check Point's management server after the company pushed fixes for two VPN certificate flaws on September 10, 2026.
2026/09/11
Threat actors exploited the newly patched CVE-2026-85103 heap overflow vulnerability in Check Point management systems to gain access, leading to a subsequent zero-day Remote Code Execution (CVE-2026-91843) via SmartConsole.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-85103
CVE-2026-91843 alert in SmartConsole (Check Point Software)
Last week,
it patched
another critical remote code execution flaw (
CVE-2026-85103
) stemming from a heap overflow in the VPN certificate ASN.1 decoding flow that affects Check Point firewalls and management systems.
tactic
T1592.002 - Software
CVE-2026-91843 alert in SmartConsole (Check Point Software)
Last week,
it patched
another critical remote code execution flaw (
CVE-2026-85103
) stemming from a heap overflow in the VPN certificate ASN.1 decoding flow that affects Check Point firewalls and management systems.
vulnerability
CVE-2026-91843
CVE-2026-91843 alert in SmartConsole (Check Point Software)
Last week,
it patched
another critical remote code execution flaw (
CVE-2026-85103
) stemming from a heap overflow in the VPN certificate ASN.1 decoding flow that affects Check Point firewalls and management systems.
tactic
Remote Code Execution
CVE-2026-91843 alert in SmartConsole (Check Point Software)
Last week,
it patched
another critical remote code execution flaw (
CVE-2026-85103
) stemming from a heap overflow in the VPN certificate ASN.1 decoding flow that affects Check Point firewalls and management systems.
September 16, 2026
Check Point issued a notice on September 16, 2026, advising customers to apply the LivePatch fix described in advisory sk1000155 due to exploitation of its management server by unknown threat actors.
Click on any entity below to view its context and source!
organisation
Check Point
Check Point said in a notice on its
CheckMates community
on September 16, 2026, that customers with automatic updates enabled are already protected, and that everyone else should apply the LivePatch fix described in advisory
sk1000155
.
September 16
Threat actors exploited a zero-day vulnerability in Check Point's management server without publicly available proof-of-concept exploit.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
The flaw was not in CISA's Known Exploited Vulnerabilities catalog as of the catalog's September 16 release, which The Hacker News checked on September 17.
attribution
Known Exploited
The flaw was not in CISA's Known Exploited Vulnerabilities catalog as of the catalog's September 16 release, which The Hacker News checked on September 17.
September 17
Threat actors exploited a zero-day vulnerability in Check Point's management server, which was not yet listed as known exploited by CISA.
Click on any entity below to view its context and source!
tactic
T1588.006 - Vulnerabilities
The flaw was not in CISA's Known Exploited Vulnerabilities catalog as of the catalog's September 16 release, which The Hacker News checked on September 17.
attribution
Known Exploited
The flaw was not in CISA's Known Exploited Vulnerabilities catalog as of the catalog's September 16 release, which The Hacker News checked on September 17.
September 18, 2026
Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed.
Click on any entity below to view its context and source!
organisation
Security Management
Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution
Pierluigi Paganini
September 18, 2026
Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed.
vulnerability
CVE-2026-91843
Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution
Pierluigi Paganini
September 18, 2026
Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed.
2026/09/23
Threat actors exploited a stack-based buffer overflow vulnerability in Check Point's Security Management Server instances, allowing them to execute code with root privileges.
Click on any entity below to view its context and source!
organisation
the Dutch National Cyber Security Centre
Two weeks ago, the Dutch National Cyber Security Centre (NCSC-NL) also
warned organizations
to urgently patch two critical Check Point VPN flaws (CVE-2026-85102 and CVE-2026-85103) because it "expects exploitation attempts to occur soon.
More recently, the Dutch National Cyber Security Centre (NCSC-NL)
warned organizations
to prioritize patching two critical Check Point VPN flaws tracked as CVE-2026-85102 and CVE-2026-85103 because it "expects exploitation attempts to occur soon.
organisation
NCSC-NL
Two weeks ago, the Dutch National Cyber Security Centre (NCSC-NL) also
warned organizations
to urgently patch two critical Check Point VPN flaws (CVE-2026-85102 and CVE-2026-85103) because it "expects exploitation attempts to occur soon.
More recently, the Dutch National Cyber Security Centre (NCSC-NL)
warned organizations
to prioritize patching two critical Check Point VPN flaws tracked as CVE-2026-85102 and CVE-2026-85103 because it "expects exploitation attempts to occur soon.
organisation
Check Point VPN
Two weeks ago, the Dutch National Cyber Security Centre (NCSC-NL) also
warned organizations
to urgently patch two critical Check Point VPN flaws (CVE-2026-85102 and CVE-2026-85103) because it "expects exploitation attempts to occur soon.
More recently, the Dutch National Cyber Security Centre (NCSC-NL)
warned organizations
to prioritize patching two critical Check Point VPN flaws tracked as CVE-2026-85102 and CVE-2026-85103 because it "expects exploitation attempts to occur soon.
organisation
CVE-2026
More recently, the Dutch National Cyber Security Centre (NCSC-NL)
warned organizations
to prioritize patching two critical Check Point VPN flaws tracked as CVE-2026-85102 and CVE-2026-85103 because it "expects exploitation attempts to occur soon.
infrastructure
Linux
After Revealing Identity
Related:
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Related:
WordPress Patches ‘Click2Shell’ Vulnerability
Related:
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
organisation
Chinese Hackers
After Revealing Identity
Related:
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Related:
WordPress Patches ‘Click2Shell’ Vulnerability
Related:
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
victims
3 Organizations
After Revealing Identity
Related:
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Related:
WordPress Patches ‘Click2Shell’ Vulnerability
Related:
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
organisation
Check Point
To resolve CVE-2026-93616, Check Point released the R82.20 Security Hotfix (TAR) and also included the fixes in the Jumbo Hotfix Accumulator for R82.10 (Take 45), R82 (Take 127), R81.20 (Take 170), and R81.10 (Take 192).
Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts.
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems.
Check Point said the attack path works only when customers use the Trusted Clients setting, which controls access to the management server through SmartConsole.
organisation
the Jumbo Hotfix Accumulator
To resolve CVE-2026-93616, Check Point released the R82.20 Security Hotfix (TAR) and also included the fixes in the Jumbo Hotfix Accumulator for R82.10 (Take 45), R82 (Take 127), R81.20 (Take 170), and R81.10 (Take 192).
organisation
LivePatch
Check Point noted that standard LivePatch updates do not resolve CVE-2026-93616.
Check Point also provided temporary mitigation measures for customers who can't deploy the latest LivePatch, including
hardening vulnerable systems
against attacks and limiting access to trusted IP addresses/subnets by editing the entries under Manage & Settings > Permissions & Administrators > Trusted Clients in the SmartConsole dashboard.
R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS)
Check Point released the fix through its LivePatch channel.
Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw has been exploited.
organisation
Check Point Management Servers
Tracked as
CVE-2026-93616
, this path traversal flaw lets unauthenticated threat actors upload arbitrary scripts on vulnerable Check Point Management Servers and execute them in low-complexity attacks.
organisation
Check Point Patches Exploited Management
Check Point Patches Exploited Management Server Zero-Day.
organisation
Security Management
According to Check Point, the flaw impacts its Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent products.
Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts.
Tracked as
CVE-2026-91843
, this flaw stems from a
stack-based buffer overflow
weakness in the login process for Security Management Server instances, which manage Security Gateways (firewalls) and monitor network security events.
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network.
organisation
Multi-Domain Security Management
According to Check Point, the flaw impacts its Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent products.
"
Check Point has addressed the vulnerability in
R82.20 Security Hotfix
and said that the complete list of affected products includes Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
organisation
SmartEvent
According to Check Point, the flaw impacts its Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent products.
"
Check Point has addressed the vulnerability in
R82.20 Security Hotfix
and said that the complete list of affected products includes Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent.
organisation
IP
As a mitigation option, customers are advised to limit access to the Management Server behind a security gateway or a firewall and limit access to port TCP/19009 to trusted IP addresses.
Check Point also provided temporary mitigation measures for customers who can't deploy the latest LivePatch, including
hardening vulnerable systems
against attacks and limiting access to trusted IP addresses/subnets by editing the entries under Manage & Settings > Permissions & Administrators > Trusted Clients in the SmartConsole dashboard.
Check Point also provides temporary mitigation measures for customers who can't immediately deploy the hotfix on vulnerable systems, including
hardening vulnerable systems
against attacks by placing them behind a firewall and limiting access to trusted IP addresses from Manage & Settings > Permissions & Administrators > Trusted Clients in the SmartConsole dashboard.
They should also limit Trusted Clients access on the management server to specific, known internal IP addresses.
Whether or not the fix is installed, check that management Trusted Clients access is limited to known, trusted hosts and is not set to any IP address, and do not expose management access directly to the internet.
organisation
The Security Management
The Security Management Server is a central repository that stores and manages security policies, processes administrator changes, and collects system logs across enterprise networks.
The Security Management Server is the system that controls firewall policy and administrator access.
organisation
Security Gateways
Tracked as
CVE-2026-91843
, this flaw stems from a
stack-based buffer overflow
weakness in the login process for Security Management Server instances, which manage Security Gateways (firewalls) and monitor network security events.
organisation
the Security Management/Log
“Censys observes
3,836 hosts
globally carrying the Security Management/Log Server role, identified by the Security Internal Communication (SIC) identity Check Point assigns management servers by default rather than by version, since build and Jumbo Hotfix level are not visible in passive scan data.”
organisation
the Security Internal Communication
“Censys observes
3,836 hosts
globally carrying the Security Management/Log Server role, identified by the Security Internal Communication (SIC) identity Check Point assigns management servers by default rather than by version, since build and Jumbo Hotfix level are not visible in passive scan data.”
infrastructure
3,836 hosts
“Censys observes
3,836 hosts
globally carrying the Security Management/Log Server role, identified by the Security Internal Communication (SIC) identity Check Point assigns management servers by default rather than by version, since build and Jumbo Hotfix level are not visible in passive scan data.”
Censys said it observes 3,836 hosts worldwide that present the default identity Check Point gives its management and log servers, a method it chose because build and hotfix level are not visible in scan data.
organisation
SmartConsole
Check Point said the attack path works only when customers use the Trusted Clients setting, which controls access to the management server through SmartConsole.
Check Point also provided temporary mitigation measures for customers who can't deploy the latest LivePatch, including
hardening vulnerable systems
against attacks and limiting access to trusted IP addresses/subnets by editing the entries under Manage & Settings > Permissions & Administrators > Trusted Clients in the SmartConsole dashboard.
Check Point also provides temporary mitigation measures for customers who can't immediately deploy the hotfix on vulnerable systems, including
hardening vulnerable systems
against attacks by placing them behind a firewall and limiting access to trusted IP addresses from Manage & Settings > Permissions & Administrators > Trusted Clients in the SmartConsole dashboard.
Check Point told The Hacker News that the vulnerable path runs only through the Trusted Clients setting, which controls which hosts may connect to the management server through SmartConsole.
organisation
Trusted Clients
Check Point said the attack path works only when customers use the Trusted Clients setting, which controls access to the management server through SmartConsole.
Whether or not the fix is installed, check that management Trusted Clients access is limited to known, trusted hosts and is not set to any IP address, and do not expose management access directly to the internet.
Editing Trusted Clients rules in SmartConsole (Check Point Software)
organisation
R80
R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS)
Check Point released the fix through its LivePatch channel.
R82.10 with Jumbo Hotfix Take 44 or below
R82 with Jumbo Hotfix Take 126 or below
R81.20 with Jumbo Hotfix Take 166 or below
R81.10 with Jumbo Hotfix Take 190 or below, and R81, R80.40, R80.30, R80.20, R80.10 and R80, all of which are end of support
The record does not list R82.20, but Abramovich said R82.20 is also vulnerable.
organisation
R80.10
R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS)
Check Point released the fix through its LivePatch channel.
organisation
R80.20
R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS)
Check Point released the fix through its LivePatch channel.
R82.10 with Jumbo Hotfix Take 44 or below
R82 with Jumbo Hotfix Take 126 or below
R81.20 with Jumbo Hotfix Take 166 or below
R81.10 with Jumbo Hotfix Take 190 or below, and R81, R80.40, R80.30, R80.20, R80.10 and R80, all of which are end of support
The record does not list R82.20, but Abramovich said R82.20 is also vulnerable.
organisation
R81
R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS)
Check Point released the fix through its LivePatch channel.
R82.10 with Jumbo Hotfix Take 44 or below
R82 with Jumbo Hotfix Take 126 or below
R81.20 with Jumbo Hotfix Take 166 or below
R81.10 with Jumbo Hotfix Take 190 or below, and R81, R80.40, R80.30, R80.20, R80.10 and R80, all of which are end of support
The record does not list R82.20, but Abramovich said R82.20 is also vulnerable.
organisation
Check Point's
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network.
organisation
Microsoft
Related:
Nightmare Eclipse Drops New Microsoft Defender Exploit
organisation
Global Properties and Data Access Control
It is the checkbox in SmartConsole, under Global Properties and Data Access Control, labeled "Automatically download and install Software Blade Contracts, security updates, and other important data (highly recommended)," followed by the installation of the Access Control policy.
organisation
Access Control
It is the checkbox in SmartConsole, under Global Properties and Data Access Control, labeled "Automatically download and install Software Blade Contracts, security updates, and other important data (highly recommended)," followed by the installation of the Access Control policy.
organisation
The Hacker News
Check Point told The Hacker News that the vulnerable path runs only through the Trusted Clients setting, which controls which hosts may connect to the management server through SmartConsole.
organisation
the Trusted Clients
Check Point told The Hacker News that the vulnerable path runs only through the Trusted Clients setting, which controls which hosts may connect to the management server through SmartConsole.
The Trusted Clients setting is in SmartConsole under Manage & Settings, Permissions & Administrators, Trusted Clients, according to the hardening guide, which also says that direct internet access to management should be avoided and that a VPN is required.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
"
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
"
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
Check Point Fixes Critical CVE-2026-91843
Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution.
organisation
SecurityAffairs
“This figure is total role presence, not a confirmed-vulnerable count.”
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, CVE-2026-91843)
organisation
CVSS
The flaw, tracked as
CVE-2026-91843
and rated 9.8 out of 10 on the CVSS scale by Check Point, is a stack overflow in the login process, which handles requests before a user is authenticated.
organisation
New Check Point
New Check Point flaw lets hackers execute code with root privileges.
organisation
Censys
Censys researchers found that an attacker can trigger the stack overflow by sending a login request with an extremely long username.
Internet scanning company Censys said the overflow is triggered by a login request that carries a very long username.
organisation
R82 Jumbo Hotfix Take
Affected versions includes
:
R82.20
R82.10 Jumbo Hotfix Take 44 or lower
R82 Jumbo Hotfix Take 126 or lower
R81.20 Jumbo Hotfix Take 166 or lower
R81.10 Jumbo Hotfix Take 190 or lower (EoS)
organisation
EoS
Affected versions includes
:
R82.20
R82.10 Jumbo Hotfix Take 44 or lower
R82 Jumbo Hotfix Take 126 or lower
R81.20 Jumbo Hotfix Take 166 or lower
R81.10 Jumbo Hotfix Take 190 or lower (EoS)
organisation
Check Point Management
As an additional security measure, organizations should follow the recommendations in the
Check Point Management and Gateway hardening best practices guide
.
organisation
Manage & Settings
The Trusted Clients setting is in SmartConsole under Manage & Settings, Permissions & Administrators, Trusted Clients, according to the hardening guide, which also says that direct internet access to management should be avoided and that a VPN is required.
organisation
Permissions & Administrators
The Trusted Clients setting is in SmartConsole under Manage & Settings, Permissions & Administrators, Trusted Clients, according to the hardening guide, which also says that direct internet access to management should be avoided and that a VPN is required.
organisation
Standalone
Standalone deployments, which run management and gateway on one system, Log Servers and Multi-Domain servers are also vulnerable, Abramovich said.
organisation
NHS England Digital
An
alert from NHS England Digital
, citing sk1000155, says the hosted Smart-1 Cloud service is not affected because the fix is already in place there.
organisation
LivePatches
The cplp list command shows which LivePatches are installed and their status.
organisation
the User Center
Customers also found that the download links in those advisories appeared only after signing in to the User Center.
organisation
Fifth Critical Management Flaw
Fifth Critical Management Flaw Since July
organisation
Lotem Finkelstein
Check Point's Lotem Finkelstein wrote then that it affected "a handful of customers" in one configuration, "when Management is exposed directly to the internet without IP restrictions."
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
After Revealing Identity
Related:
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Related:
WordPress Patches ‘Click2Shell’ Vulnerability
Related:
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Metrics
victims
3
Organizations
After Revealing Identity
Related:
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Related:
WordPress Patches ‘Click2Shell’ Vulnerability
Related:
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Metrics
infrastructure
3,836
Hosts
“Censys observes
3,836 hosts
globally carrying the Security Management/Log Server role, identified by the Security Internal Communication (SIC) identity Check Point assigns management servers by default rather than by version, since build and Jumbo Hotfix level are not visible in passive scan data.”
Censys said it observes 3,836 hosts worldwide that present the default identity Check Point gives its management and log servers, a method it chose because build and hotfix level are not visible in scan data.
Intelligence Sources
Security Affairs
2026-09-18
SecurityWeek
2026-09-23
BleepingComputer
2026-09-22
Check Point warns of Management Server zero-day exploited in attacks
BleepingComputer
The Hacker News
2026-09-17
BleepingComputer
2026-09-18
New Check Point flaw lets hackers execute code with root privileges
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:32
Comprehensive Tactical Telemetry
Highly Correlated Entities
54x
organisation
Identified Entity
Known Exploited
entity
13x
timeline
Temporal Reference
September 9
date
9x
vulnerability
Exploited CVE
CVE-2026-85102
cve
7x
attribution
Attributing Entity
CISA
authority
4x
tactic
Cyber Operation Type
Ransomware
tactic
3x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
malware
Malware Payload
Spark
tool
2x
general metric
R81.20
170
r81.20
2x
general metric
Hotfix
126
hotfix
Contextual Telemetry
Context Block
8 METRICS
source region
Origin Country
United States
country
vulnerability
CVSS Score
10
score
general metric
R82
127
r82
infrastructure
Affected Product
Linux
software
victims
Organizations
3
organizations
general metric
Eos
190
eos
infrastructure
Hosts
3,836
hosts
general metric
Cve-2026
10
cve-2026
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.