CVE-2026-91843
CVSS 9.8 CRITICAL: a stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with…
Vulnerabilità · 3 giorni fa
Check Point ha corretto CVE-2026-91843, una stack overflow critica nel login pre-auth di Security Management Server e Log Server che può portare a code execution come root senza credenziali. La falla colpisce anche Multi-Domain Security Management e, secondo Check Point, include R82.20.
Il difetto si attiva su Trusted Clients: una richiesta di login con username molto lungo può mandare in overflow la memoria prima dell’autenticazione. Poiché il guasto è nella porta d’ingresso del piano di gestione, chi lo sfrutta può prendere il controllo del server che decide policy firewall e accesso amministrativo.
Per chi espone l’interfaccia di gestione a host Trusted Clients più permissivi del necessario, il raggio d’azione è il punto critico. Check Point dice di non avere evidenza di sfruttamento, ma la superficie colpita è il piano che governa il resto della flotta, quindi la patch va trattata come urgente.
CVSS 9.8 CRITICAL: a stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with…
5 fonti che coprono questa storia
Kwetsbaarheid verholpen in Check Point's Security Management and Log Servers
Check Point heeft een kwetsbaarheid verholpen in Check Point's Security Management and Log Servers.
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.
New Check Point flaw lets hackers execute code with root privileges
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems.
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
Check Point patched CVE-2026-91843, a critical login stack overflow that can let unauthenticated attackers run code as root on management servers.
Desbordamiento de búfer basado en pila en Security Management y Log Servers de Check Point
Check Point ha publicado una vulnerabilidad crítica de desbordamiento de búfer basado en pila durante
Part of the PlainSec briefing for 2026-09-21