The server that manages a fleet of firewalls is a tempting place to land, because whoever holds it holds the policy for everything behind it. Check Point has patched a flaw in exactly that box, rated 9.8 out of 10, that lets an attacker with no credentials run code on it as root.
The bug is CVE-2026-91843, a stack overflow that happens during the unauthenticated login process. Nothing has to be stolen or guessed first.
Management and log servers, but not Smart-1 Cloud
Check Point's advisory covers the Security Management Server, the Multi-Domain Security Management Server, the Log Server and the Multi-Domain Log Server. Smart-1 Cloud is not affected. The vulnerable builds are R82.20, R82.10 at Jumbo Hotfix Take 44 or lower, R82 at Take 126 or lower, R81.20 at Take 166 or lower, R81.10 at Take 190 or lower, and every R80.x and R81 release, all of which are past end of support.
That last clause is the uncomfortable one. The advisory names LivePatch bundles for R82.20 (Take 29), R82.10 (Take 28), R82 (Take 28) and R81.20 (Take 28). An estate still running an end-of-support train is holding a 9.8 with no bundle listed against it, and the fix there is a version upgrade rather than a hotfix.
Install the LivePatch, then check it armed
Administrators should take the bundle for their version from Check Point's advisory sk1000155 and confirm it is live by running cplp list in Expert mode. Deployments with automatic updates already enabled are protected without any action. As an interim measure the advisory recommends restricting Trusted Clients in SmartConsole to specific IP addresses or subnets rather than leaving the client type set to Any, which is sound practice for a management interface whether or not this particular bug is in play.
Check Point flagged the fix in its own weekly threat intelligence report on 21 September. The advisory does not report any exploitation in the wild, and the company's framing is preventative rather than reactive.
Security gear keeps failing at the front door
The pattern is getting hard to ignore. Pre-authentication paths in security products have produced a run of critical findings this month, and not all of them stayed theoretical: Cisco's Identity Services Engine is being bypassed in live attacks after a flaw rated a perfect 10. These boxes sit at the boundary, answer unauthenticated requests by design, and hold the privileges needed to reconfigure everything else. A login routine that trusts its input too early is worth more to an attacker here than almost anywhere else on the network.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.