Vulnerability threat dossier

CVE-2026-91843

checkpointQuantum Security Management

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

VTP deterministic threat20.6of 100 · CVSS excluded

VTP analyst assessment

Check Point Quantum Security Management login stack overflow

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence68%
Public exploitation · VTP factREPORTED

Assessment

CVE-2026-91843 is a stack overflow in the unauthenticated login process of Check Point Quantum Security Management. Successful exploitation can provide remote arbitrary code execution with root privileges. BleepingComputer reported exploitation, but the available excerpt does not identify a campaign or targets.

Why it matters

  • An exposed management login service gives an attacker a direct path to the system that administers security infrastructure.
  • Root-level code execution could allow takeover of the management server.
  • If you use Quantum Security Management, apply Check Point's security update and limit access to its login service.

Evidence

2 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

Public reporting of exploitation is available, but the supplied report does not identify the affected organizations or exploitation details.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use the product, verify that management login interfaces are not broadly reachable.

AI baseline history (5)
  1. BASELINE ASSESSED
    Check Point Quantum Security Management login stack overflowgpt-5.6-terra · low
  2. BASELINE ASSESSED
    Check Point management login stack overflowgpt-5.6-terra · low
  3. BASELINE ASSESSED
    Check Point management-server unauthenticated root code executiongpt-5.6-terra · low
  4. BASELINE ASSESSED
    Reported Check Point management-server vulnerabilitygpt-5.6-terra · low
  5. BASELINE ASSESSED
    Check Point remote code execution vulnerability reportedgpt-5.6-terra · low
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0142th percentile · prediction
Evidence confidence60%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.01; this is predictive context, not exploitation evidence.

  2. 02

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

CERT ADVISORYNew CERT advisory
03

Claim provenance

Evidence and source independence

6publications detected
6underlying evidence chains

1 primary sources · 0 dependent secondary reports · 5 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:1d67634bfd055f8b66243743993d7ccb788cb776cfcafda8a267d92a581c5a94ACTIVE
Evidence
04

Event history

Threat timeline

  1. 09:3418 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 00:0017 Sept
    CERT ADVISORY

    New CERT advisory

    CERT-FR published evidence linked to CVE-2026-91843.

05

Original publications

Source record

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point

CVE-2026-85102CVE-2026-85103CVE-2026-91843CVE-2026-93616
Separate evidence group
Original

⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not

CVE-2025-43936CVE-2026-0310CVE-2026-15315CVE-2026-15316CVE-2026-18851CVE-2026-19666CVE-2026-19667CVE-2026-28302CVE-2026-28304CVE-2026-28305CVE-2026-28306CVE-2026-28307CVE-2026-28308CVE-2026-28309CVE-2026-28310CVE-2026-28311CVE-2026-28312CVE-2026-28313CVE-2026-28314CVE-2026-28315CVE-2026-28316CVE-2026-28317CVE-2026-28321CVE-2026-28323CVE-2026-28326CVE-2026-32882CVE-2026-39919CVE-2026-43502CVE-2026-43790CVE-2026-56711CVE-2026-58138CVE-2026-58704CVE-2026-61410CVE-2026-65346CVE-2026-65400CVE-2026-65414CVE-2026-65638CVE-2026-65812CVE-2026-68121CVE-2026-68488CVE-2026-70416CVE-2026-73178CVE-2026-73324CVE-2026-73693CVE-2026-73694CVE-2026-73698CVE-2026-73699CVE-2026-74469CVE-2026-76163CVE-2026-76460CVE-2026-76669CVE-2026-76670CVE-2026-76672CVE-2026-76673CVE-2026-76674CVE-2026-77147CVE-2026-77179CVE-2026-77692CVE-2026-78175CVE-2026-78623CVE-2026-78626CVE-2026-80172CVE-2026-80238CVE-2026-80274CVE-2026-80844CVE-2026-81000CVE-2026-81642CVE-2026-82079CVE-2026-82232CVE-2026-82717CVE-2026-84607CVE-2026-85061CVE-2026-85982CVE-2026-89026CVE-2026-89049CVE-2026-90894CVE-2026-90999CVE-2026-91721CVE-2026-91726CVE-2026-91749CVE-2026-91843CVE-2026-91931CVE-2026-91932CVE-2026-91998CVE-2026-92005CVE-2026-92013CVE-2026-92015CVE-2026-92020CVE-2026-92022CVE-2026-92029CVE-2026-92033CVE-2026-92034CVE-2026-92038CVE-2026-93372CVE-2026-93374
Separate evidence group
Original

New Check Point flaw lets hackers execute code with root privileges

Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. [...]

CVE-2026-16232CVE-2026-50751CVE-2026-85102CVE-2026-85103CVE-2026-91843
Separate evidence group
Original

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek .

CVE-2026-91843
Separate evidence group
Original

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw

CVE-2026-16232CVE-2026-18574CVE-2026-62144CVE-2026-85103CVE-2026-91843
Separate evidence group
Original

Vulnérabilité dans les produits Check Point (17 septembre 2026)

Une vulnérabilité a été découverte dans les produits Check Point. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Checkpoint recommande de rechercher, via la *SmartConsole*, le motif **"Administrator failed to log in: Username too long"** dans les journaux...

CVE-2026-91843
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score20.6vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction0.1 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency6 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-121
CPE records
0
Deterministic history records
12
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.