LATEST View all updates

Check Point CVE-2026-91843: Affected Versions and LivePatch Fix

Check Point says CVE-2026-91843 can enable root RCE; affected management and log servers need immediate LivePatch verification.

Editorial illustration of a critical remote-code-execution vulnerability affecting enterprise security management servers

Signal Brief

  • Check Point says CVE-2026-91843 is a CVSS 9.8 unauthenticated flaw that may enable remote root-level code execution on affected management and log servers.
  • Administrators should verify affected release/take combinations and confirm that the required LivePatch from sk1000155 is actually installed.
  • Check Point currently reports no indication of in-the-wild exploitation, but that state can change quickly.
  • R82.20 is listed as affected by Canadian and NHS advisories even though the reviewed public CNA rendering did not list it, so Check Point's live advisory should control remediation.

CVE-2026-91843 is a critical Check Point vulnerability affecting Security Management and Log Server infrastructure. Check Point says the flaw can be reached through the unauthenticated login process and may allow a remote attacker to execute arbitrary code with root privileges. The vulnerability carries a CVSS 3.1 score of 9.8.

Administrators should verify both their affected product role and their current LivePatch state. Check Point recommends immediate installation of the LivePatch described in sk1000155. The company says customers protected by automatic updates are already covered, but TPS recommends treating that as a vendor-reported protection state that still needs operational verification in the actual environment.

Check the server role

Confirm whether the system is a Security Management Server, Multi-Domain Security Management Server, Log Server or Multi-Domain Log Server.

Check release and Jumbo Hotfix take

Compare the installed release and take against the affected-version guidance below and the current Check Point advisory.

Verify LivePatch protection

If automatic updates are enabled, confirm that the required protection actually appears as installed. Otherwise follow Check Point’s LivePatch instructions in sk1000155.

Monitor exploitation state

Check Point currently says it has no indication of exploitation in the wild. Reassess immediately if the vendor, CISA or another trusted authority changes that state.

What CVE-2026-91843 affects

The disclosed scope centers on Check Point management and logging infrastructure rather than a blanket statement that every Check Point firewall or Security Gateway is vulnerable.

The affected product roles identified in reviewed advisories include Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server.

That distinction matters for Standalone environments, where gateway and management functions may coexist. Administrators should verify the actual management-server component and current vendor guidance rather than assuming that the gateway role alone determines exposure.

Infographic summarizing CVE-2026-91843 affected Check Point releases and LivePatch guidance
Supported affected release thresholds include R81.20, R82 and R82.10, with R82.20 also listed by national cyber advisories.

Affected supported versions and Jumbo Hotfix takes

National cyber-security advisories reviewed by TPS list the following supported release states as affected:

  • R81.20 — Jumbo Hotfix Take 166 and prior.
  • R82 — Jumbo Hotfix Take 126 and prior.
  • R82.10 — Jumbo Hotfix Take 44 and prior.
  • R82.20 — listed as affected in Canadian and NHS advisories reviewed by TPS.

Check Point’s public CNA/CVE record also lists older R81.10 and multiple R80/R81 end-of-support branches as affected.

The exact live vendor matrix should control remediation because patch state can change after publication.

Why R82.20 needs a careful note

TPS found a version-matrix discrepancy across reviewed sources. The public Check Point CNA rendering reviewed during R&D did not list R82.20, while the Canadian Centre for Cyber Security and NHS England advisories explicitly included R82.20 among affected releases.

For publication, TPS is treating R82.20 as affected based on those current national cyber-security advisories while directing administrators back to Check Point’s live sk1000155 matrix for the controlling remediation state.

This discrepancy should not be interpreted as evidence that R82.20 is safe.

What the vulnerability can allow

Check Point describes CVE-2026-91843 as a stack-based buffer overflow in the login process. The CVSS vector is network reachable, low complexity, requires no prior privileges and requires no user interaction.

Successful exploitation may allow arbitrary code execution with root privileges on an affected management or log server. Because these systems are part of the security-management control plane, compromise could have broader operational consequences than a vulnerability in an isolated endpoint.

What Check Point recommends

Check Point recommends immediate installation of the relevant LivePatch from the vendor’s current security advisory.

The company says customers using automatic updates are already protected. Administrators should still confirm that the protection is present rather than assuming that an intended automatic-update configuration guarantees successful deployment in every environment.

Systems on older or end-of-support branches may require a different remediation or upgrade path, so those environments should be checked directly against current Check Point support guidance.

Is CVE-2026-91843 being exploited?

Check Point currently says it has no indication of exploitation in the wild.

That statement is time-sensitive. It does not mean exploitation is impossible, and it should not be converted into a claim that the vulnerability has never been exploited. TPS will monitor for vendor changes, CISA KEV inclusion, public proof-of-concept reporting and indicators of compromise.

What about Smart-1 Cloud?

NHS England’s reviewed advisory states that Smart-1 Cloud is not affected because the relevant fix had already been implemented server-side.

Cloud customers should still follow current Check Point service guidance if the vendor later changes that status.

How to verify whether your environment is protected

Start with the management-server role, release and Jumbo Hotfix take. Then verify whether the required LivePatch is installed.

Do not use the CVSS score alone as a remediation check. A system can remain on an affected software train while being protected by a vendor LivePatch, and an administrator can also have automatic updates configured without having independently confirmed the patch state.

The operational question is therefore not simply, “Am I running R82?” It is, “Is this product role within the affected scope, and is the required vendor protection actually present?”

What TPS is monitoring next

This article should be updated on the same URL if Check Point revises the affected-version matrix, releases new LivePatch or Jumbo Hotfix guidance, confirms exploitation, publishes indicators of compromise, or if CISA adds CVE-2026-91843 to the Known Exploited Vulnerabilities catalog.

A separate article would only be justified if the reader problem materially changes, such as a later need to determine whether an environment was compromised and how to perform incident response after confirmed exploitation.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led article for informational and editorial guidance on CVE-2026-91843. Check Point confirms a critical unauthenticated remote-code-execution risk and recommends immediate LivePatch action, but current exploitation, environment-specific patch success and some version-matrix details can change. Verify the controlling Check Point advisory and current vendor guidance before making consequential security or remediation decisions.