Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-91843: Checkpoint Quantum Security Management allows remote code execution via login

CVE-2026-91843 · published 25 days ago
Summary

The login function in Checkpoint Quantum Security Management can overflow its memory when accessed without authentication. This flaw could let an attacker execute their own programs on the server with full administrative rights. Apply the vendor's security update or disable the unauthenticated login feature until a patch is installed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
checkpoint quantum security management R82.10 with Jumbo Hotfix Take 44 or below
Original advisory text
Stack overflow in login process to the Security Management and Log Servers
A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-121Stack-based Buffer Overflow
Timeline
Published16 Sep 2026
Updated11 Oct 2026
First seen16 Sep 2026
Sources
CVE-2026-91843 · MITRE
Track software like this
Free during beta