CVE-2026-91843
Check Point Quantum Security Management stack overflow allows unauthenticated remote code execution (CVE-2026-91843)
Check Point Quantum Security Management has a critical pre-authentication stack overflow in the login process. No fixed release or vendor workaround is listed yet, so restrict access to management and log servers and monitor for unusual activity.
What happened
Check Point has disclosed CVE-2026-91843, a stack overflow in the unauthenticated login process used by Quantum Security Management and Log Servers. The flaw is reachable over the network, requires no credentials and no user interaction, and has low attack complexity. Successful exploitation may allow an attacker to run arbitrary code remotely with root privileges. The CVSS v3.1 base score is 9.8 (Critical).
No exploitation is recorded in the data Check Point has provided, and CISA's KEV catalogue does not list this CVE. Check Point has not published a vendor statement on exploitation. No fixed release or vendor workaround is listed yet.
Who is affected
The affected product is Check Point Quantum Security Management, including the Security Management and Log Servers. The advisory identifies:
- R82.10 with Jumbo Hotfix Take 44 or below
- R82 with Jumbo Hotfix Take 126 or below
- R81.20 with Jumbo Hotfix Take 166 or below
- R81.10 (end of support) with Jumbo Hotfix Take 190 or below
- R81, R80.40, R80.30 and R80.20 (all end of support)
These are management-plane systems rather than enforcement gateways, so they normally sit on privileged internal networks. Any deployment where the management or log server login interface is reachable from a broader network should be treated as exposed until access is restricted.
What to do now
- Confirm whether your Quantum Security Management version is in the affected list above. If it is, treat the login interface as exploitable until Check Point publishes a fixed release.
- No fixed version or vendor workaround is currently listed in Check Point advisory sk1000155. Do not rely on a hotfix unless Check Point explicitly names one in an update.
- Restrict access to Security Management and Log Servers to dedicated management networks or trusted administrative hosts. Remove any internet-facing exposure or firewall rules that permit broad access to the login service.
- Where the servers cannot be isolated immediately, apply compensating network controls and monitor the login service for unexpected restarts, crashes, or unexpected remote login attempts.
- Re-check the Check Point advisory regularly for updated fix guidance.
Beyond the patch
Beyond the immediate exposure, this is a reminder that management platforms are high-value targets. Because the flaw requires no credentials and can be exploited over the network, the first question is whether your Security Management or Log Server is reachable from anywhere it should not be — exactly the kind of exposure that Virtual CISO Services (vCISO) can review. Check Point is a software vendor in your estate; our Supply Chain Defense & Third-Party Risk service can track this advisory until Check Point publishes a fix and help you plan the upgrade.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Quantum Security Management | R82.10 with Jumbo Hotfix Take 44 or below R82 with Jumbo Hotfix Take 126 or below R81.20 with Jumbo Hotfix Take 166 or below R81.10 (EOS) with Jumbo Hotfix Take 190 or below R81 (EOS) R80.40 (EOS) R80.30 (EOS) R80.20 (EOS) | No fixed version listed yet |