Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
_Val_
Admin
Admin

[Important Notification] Action required - Critical Security Update (CVE-2026-91843) - Sep 16th 202

 
Please be advised regarding a critical vulnerability, CVE-2026-91843 (CVSS Score 9.8), affecting Check Point Security Management and Log Servers
 
This vulnerability may allow an unauthenticated attacker to remotely execute arbitrary code with root privileges through the login process.

At this time, there is no indication that this vulnerability has been exploited in the wild. However, due to its critical severity and potential impact, we strongly recommend taking immediate action to protect your environment.


Required actions
 
 
If you have any questions or need assistance assessing your environment, please contact Check Point Support or reach out to your Check Point representative – we are here to help.

Thank you for your prompt attention to this matter.
 
7 Replies
PecenkA
Participant

Windows Security flags urgent_security_updates_R82_Bundle_T28_AutoUpdate.tar as Trojan:Script/Wacatac.H!ml

0 Kudos
(1)
RemoteUser
Advisor

S1C Users are impacted?

0 Kudos
PhoneBoy
Admin
Admin

As stated in sk1000155: The Smart-1 Cloud environment is not affected because the fix has already been implemented there.

WiliRGasparetto
MVP Diamond
MVP Diamond

por isos a importância de usar o Check Point Live Patch falo sobre isso no post: https://community.checkpoint.com/t5/Firewall-Security-Management/Check-Point-Live-Patch-Why-sk185114...

0 Kudos
WiliRGasparetto
MVP Diamond
MVP Diamond

 
 
 

To illustrate the importance of deploying the CPLP: an engineer from our team went to check on a client regarding today's CVE, and it had already been automatically remediated here is the screenshot showing zero impact on the environment.WhatsApp Image 2026-09-16 at 12.47.06.jpeg

0 Kudos
DominusRex23
Participant

Hi, are standalone deployments affected as well?

0 Kudos
StackCap43382
Advisor
Advisor

The impacted process is the FWM process which is used for authentication.

A stand-alone Manager-GW deployment still has the FWM process so IS at risk and needs Patch 28 of CPLP.

CCSME, CCTE, CCME, CCVS
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events