Search/CVE-2026-91843
CVE — Critical

CVE-2026-91843

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

CVSS v3.1
9.8 CRITICAL
EPSS
0.50%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
3
sources referencing this CVE
CVSS v3.1 Detail
Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Connections
5 relationships
Timeline
disclosure → media coverage
Sep 16, 2026
Disclosure — published as a CVE record.
Sep 17, 2026
thehackernews.com reports: Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
Sep 18, 2026
securityweek.com reports: Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Sep 18, 2026
bleepingcomputer.com reports: New Check Point flaw lets hackers execute code with root privileges
Public PoC (1)
Unverified third-party code — review before executing.