<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [Important Notification] Action required - Critical Security Update (CVE-2026-91843) - Sep 16th in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282464#M47074</link>
    <description>&lt;P&gt;The impacted process is the FWM process which is used for authentication.&lt;/P&gt;&lt;P&gt;A stand-alone Manager-GW deployment still has the FWM process so IS at risk and needs Patch 28 of CPLP.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Sep 2026 08:37:28 GMT</pubDate>
    <dc:creator>StackCap43382</dc:creator>
    <dc:date>2026-09-17T08:37:28Z</dc:date>
    <item>
      <title>[Important Notification] Action required - Critical Security Update (CVE-2026-91843) - Sep 16th 202</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282409#M47058</link>
      <description>&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT size="4"&gt;Please be advised regarding a critical vulnerability, &lt;STRONG&gt;CVE-2026-91843 (CVSS Score 9.8)&lt;/STRONG&gt;, affecting &lt;STRONG&gt;Check Point Security Management and Log Servers&lt;/STRONG&gt;.&amp;nbsp;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT size="4"&gt;This vulnerability may allow an unauthenticated attacker to remotely execute arbitrary code with root privileges through the login process.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;At this time, &lt;STRONG&gt;there is no indication that this vulnerability has been exploited in the wild&lt;/STRONG&gt;. However, due to its critical severity and potential impact, we strongly recommend taking immediate action to protect your environment.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;Required actions&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT size="4"&gt;Apply the LivePatch fix as described in &lt;A id="OWAae209a4d-96ea-5810-1d20-3ff42112aed7" class="OWAAutoLink" title="Protected by Check Point: https://support.checkpoint.com/results/sk/sk1000155" href="https://protect.checkpoint.com/v2/r02/___https://support.checkpoint.com/results/sk/sk1000155___.YzJlOmNwYWxsOmM6bzowZTlhMWQ0ZjQ2NGFlM2JhOGMzNWIxMTczMmJiMWNmYTo3OmM0Y2E6MGYxNjAyNWQ0ZmNlM2FmNTM0YjFiYjc4ZTgyYTJjNDEwN2I3OTEyMDc0ZTUzODBiZGRkNzRmNzM4ZDA5MDk3NDpoOlQ6Tg" data-auth="NotApplicable" target="_blank"&gt;sk1000155&lt;/A&gt;&amp;nbsp;- customers with automatic updates enabled are already protected.&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT size="4"&gt;As a mitigation, follow the instructions in the &lt;A id="OWAa0ac88f1-b53f-1920-a763-dd508eae9ce1" class="OWAAutoLink" title="Protected by Check Point: https://sc1.checkpoint.com/documents/Check_Point_Gateway_and_Management_Hardening/CP_Check_Point_Gateway_and_Management_Hardening.pdf" href="https://protect.checkpoint.com/v2/r02/___https://sc1.checkpoint.com/documents/Check_Point_Gateway_and_Management_Hardening/CP_Check_Point_Gateway_and_Management_Hardening.pdf___.YzJlOmNwYWxsOmM6bzowZTlhMWQ0ZjQ2NGFlM2JhOGMzNWIxMTczMmJiMWNmYTo3OjFlZWI6YjhmZjNiNTBmYzc0ZDJiZGRkNDc2YzY1MGU5YzdlMDRiYjM1ZWNkZmI0ZWI1N2I4ODg0NjM5MGYyZjM0OWVjYzpoOlQ6Tg" data-auth="NotApplicable" target="_blank"&gt;Check Point Management and Gateway hardening best practices guide&lt;/A&gt;, and limit management Trusted Clients access to known, specific internal IP addresses.&lt;/FONT&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT size="4"&gt;If you have any questions or need assistance assessing your environment, please contact &lt;A id="OWA598dbf5e-4061-94da-c7a8-029546dd8bd2" class="OWAAutoLink" title="Protected by Check Point: https://www.checkpoint.com/support-services/contact-support/" href="https://protect.checkpoint.com/v2/r02/___https://www.checkpoint.com/support-services/contact-support/___.YzJlOmNwYWxsOmM6bzowZTlhMWQ0ZjQ2NGFlM2JhOGMzNWIxMTczMmJiMWNmYTo3OjUyYTk6NGU5NGUzMjA5MjAzYzk2NjdjZDAxN2JjYmFkOTMzNjc4NDVjMzQyOTZlYzhmYzYzOTRjOWRlMzhjODVhNDAyMTpoOlQ6Tg" data-auth="NotApplicable" target="_blank"&gt;Check Point Support &lt;/A&gt;or reach out to your Check Point representative – we are here to help.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT size="4"&gt;Thank you for your prompt attention to this matter.&lt;/FONT&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;FONT size="4"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 16 Sep 2026 13:06:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282409#M47058</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2026-09-16T13:06:38Z</dc:date>
    </item>
    <item>
      <title>Re: [Important Notification] Action required - Critical Security Update (CVE-2026-91843) - Sep 16th</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282410#M47059</link>
      <description>&lt;P&gt;Windows Security flags &lt;SPAN&gt;urgent_security_updates_R82_Bundle_T28_AutoUpdate.tar as&amp;nbsp;Trojan:Script/Wacatac.H!ml&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2026 13:40:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282410#M47059</guid>
      <dc:creator>PecenkA</dc:creator>
      <dc:date>2026-09-16T13:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: [Important Notification] Action required - Critical Security Update (CVE-2026-91843) - Sep 16th</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282411#M47060</link>
      <description>&lt;P&gt;S1C Users are impacted?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2026 14:01:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282411#M47060</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-09-16T14:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: [Important Notification] Action required - Critical Security Update (CVE-2026-91843) - Sep 16th</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282414#M47061</link>
      <description>&lt;P&gt;por isos a importância de usar o Check Point Live Patch falo sobre isso no post: &lt;A href="https://community.checkpoint.com/t5/Firewall-Security-Management/Check-Point-Live-Patch-Why-sk185114-Changes-the-Operational/m-p/282373#M106773" target="_blank"&gt;https://community.checkpoint.com/t5/Firewall-Security-Management/Check-Point-Live-Patch-Why-sk185114-Changes-the-Operational/m-p/282373#M106773&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2026 14:31:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282414#M47061</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-09-16T14:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: [Important Notification] Action required - Critical Security Update (CVE-2026-91843) - Sep 16th</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282424#M47062</link>
      <description>&lt;P&gt;As stated in&amp;nbsp;&lt;SPAN&gt;sk1000155:&amp;nbsp;The Smart-1 Cloud environment is not affected because the fix has already been implemented there.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2026 15:35:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282424#M47062</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-09-16T15:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: [Important Notification] Action required - Critical Security Update (CVE-2026-91843) - Sep 16th</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282426#M47063</link>
      <description>&lt;DIV id="tinyMceEditor_480a71406f2039WiliRGasparetto_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditor_480a71406f2039WiliRGasparetto_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditor_480a71406f2039WiliRGasparetto_2" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;To illustrate the importance of deploying the CPLP: an engineer from our team went to check on a client regarding today's CVE, and it had already been automatically remediated here is the screenshot showing zero impact on the environment.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2026-09-16 at 12.47.06.jpeg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35308i9D532012BDAA3434/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2026-09-16 at 12.47.06.jpeg" alt="WhatsApp Image 2026-09-16 at 12.47.06.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2026 15:55:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282426#M47063</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-09-16T15:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: [Important Notification] Action required - Critical Security Update (CVE-2026-91843) - Sep 16th</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282450#M47070</link>
      <description>&lt;P&gt;Hi, are standalone deployments affected as well?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2026 02:04:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282450#M47070</guid>
      <dc:creator>DominusRex23</dc:creator>
      <dc:date>2026-09-17T02:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: [Important Notification] Action required - Critical Security Update (CVE-2026-91843) - Sep 16th</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282464#M47074</link>
      <description>&lt;P&gt;The impacted process is the FWM process which is used for authentication.&lt;/P&gt;&lt;P&gt;A stand-alone Manager-GW deployment still has the FWM process so IS at risk and needs Patch 28 of CPLP.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2026 08:37:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Important-Notification-Action-required-Critical-Security-Update/m-p/282464#M47074</guid>
      <dc:creator>StackCap43382</dc:creator>
      <dc:date>2026-09-17T08:37:28Z</dc:date>
    </item>
  </channel>
</rss>

