Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
CVE-2026-91843 is a critical stack-based buffer overflow in the login process of self-managed Check Point Quantum Security Management Server and Log Server, including Multi-Domain deployments. The login path is unauthenticated, so an attacker does not need valid credentials to reach the flaw. Censys reports a CVSS v3.1 base score of 9.8 for the issue, assigned by Check Point, and the vulnerability was disclosed on September 16, 2026. Check Point distributes the fix as a LivePatch, not as a standalone build, so the practical work is to confirm which servers fall inside the affected ranges, install the matching LivePatch Take, and verify that it is active. If patching cannot happen immediately, restrict management web access to trusted clients while you schedule the update. Servers on end-of-support branches have no fix in this advisory and need a supported upgrade path.
What the vulnerability is and how the attack path works
The flaw sits in the unauthenticated login process of the management and log server software. Censys describes the attack as a crafted login request containing an excessively long username field. Because that field is copied into a fixed-size buffer on the stack, the overflow can overwrite adjacent memory and, according to Censys, may allow remote arbitrary code execution with root privileges (Censys advisory, September 16, 2026).
Three points matter for risk assessment. First, the request reaches the login service before any authentication occurs, so a valid administrator account provides no protection against this path. Second, the public advisories do not identify the exact vulnerable function or memory layout, and they do not describe a reproducible exploit chain. Third, exploitation is a remote-code-execution outcome, which is why the affected-build check and the patch are both urgent even though no public exploit had been reported at the time of the advisories.
Which deployments are affected
The affected scope covers self-managed Quantum Security Management Server and Log Server deployments, including Multi-Domain variants. Smart-1 Cloud is reported as not affected (Censys advisory; CERT.LV advisory, September 18, 2026). The CERT.LV advisory is published in Latvian, so consult that page for its exact wording.
#1 Best Overall
Affected status depends on two values on each server: the release branch and the installed Jumbo Hotfix Take. The thresholds below are Jumbo Hotfix Take numbers. They are not the LivePatch Take numbers used for the fix, and mixing the two is the most common way to misjudge exposure. A server is in the affected range when its Jumbo Hotfix Take is at or below the listed value.
| Release | Affected level reported | Support and fix status in the advisories |
|---|---|---|
| R82.20 | All versions. No Jumbo Hotfix Take provided protection. | Supported. Apply LivePatch Take 29. |
| R82.10 | Jumbo Hotfix Take 44 or lower | Supported. Apply LivePatch Take 28. |
| R82 | Jumbo Hotfix Take 126 or lower | Supported. Apply LivePatch Take 28. |
| R81.20 | Jumbo Hotfix Take 166 or lower | Supported. Apply LivePatch Take 28. |
| R81.10 | Jumbo Hotfix Take 190 or lower | End of support. No fix in this advisory; migrate. |
| R81, R80.40, R80.30, R80.20, R80.10, R80 | All versions | End of support. No fix in this advisory; migrate. |
The advisory summary states that the same release and Take ranges apply to Multi-Domain variants. On Multi-Domain installations, check the Multi-Domain Server and each Log Server separately, because each has its own installed build and LivePatch state.
Fixed LivePatch Takes and how to apply them
Check Point delivers the fix through LivePatch. The patched Takes reported for the four supported branches are R82.20 Take 29, R82.10 Take 28, R82 Take 28, and R81.20 Take 28 (Censys advisory). CERT.LV lists the same fixed Takes (CERT.LV advisory). Check Point automatic-update enrollment may deliver the patch, but automatic delivery is not proof of installation, so verify each server.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
- On each affected management or log server, record the release and the installed Jumbo Hotfix Take.
- Compare the release against the table above. If the server is on a supported branch and at or below the affected Jumbo Hotfix threshold, it needs the LivePatch.
- Install the LivePatch Take listed for that branch: Take 29 for R82.20, or Take 28 for R82.10, R82, or R81.20.
- Run
cplp liston the server. CERT.LV states that a successful installation shows a patch comment readingCVE-2026-91843. - If the comment is missing, treat the server as unpatched. Do not rely on the update channel having applied the patch, and do not close the item until the comment appears on that specific server.
Record the result per server, including Multi-Domain Servers and Log Servers. A patched management server with an unpatched log server still leaves a path open on the log side.
End-of-support branches
R81.10, R81, and the R80.x branches are end of support. Censys reports that this advisory provides no fix for them, which makes migration to a supported branch the stated remediation path (Censys advisory). Confirm with Check Point support whether any exception or interim guidance applies to your contract before you plan around it. Until the migration is complete, these servers should be the first candidates for the interim restriction described next.
Interim hardening when patching is delayed
If a server cannot take the LivePatch immediately, CERT.LV recommends limiting the management web interface to trusted clients using Check Point Trusted Clients. The navigation path cited in that advisory is Manage & Settings > Permissions & Administrators > Trusted Clients (CERT.LV advisory). Limit the list to the administrator workstations and jump hosts that genuinely need web access, and confirm that management access from other networks is blocked.
This restriction reduces exposure while the update is scheduled. It does not remove the vulnerable code, and it does not change the status of an unpatched server. Treat it as a bridge to the LivePatch or the migration, not as the fix.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Exploitation status and what the exposure numbers mean
At the time of its advisory, Censys reported no public proof-of-concept and no confirmed exploitation, and it said the CVE was not listed in the CISA Known Exploited Vulnerabilities catalog (Censys advisory, September 16, 2026). These are dated observations. Treat “not confirmed” as a status that may change, not as evidence that a system is safe.
Best Value
Censys observed 3,836 hosts carrying the Check Point cp_mgmt SIC identity associated with Security Management and Log Servers in 2026; that count reflects server-role presence, not a confirmed vulnerable population, because passive scan data did not reveal the software build or Jumbo Hotfix level. Use it to gauge how many internet-visible Check Point management roles exist, then verify your own estate against the build table.
Decision guide for each server
| Server state | Action |
|---|---|
| Supported branch, in affected range, LivePatch not installed | Install the listed LivePatch Take now. If that is not possible, restrict trusted clients immediately and schedule the patch. |
Supported branch, in affected range, cplp list shows the CVE-2026-91843 comment |
Record as patched. Keep the trusted-client restriction in place if it was added as a temporary measure. |
| Supported branch, above the affected Jumbo Hotfix threshold | Confirm the build with the records you hold, then keep the server on the standard patch schedule. |
| R81.10, R81, or R80.x (end of support) | Restrict trusted clients now and plan migration to a supported branch. |
| Smart-1 Cloud | Reported as not affected. Confirm with your vendor contact that the tenant is a Smart-1 Cloud deployment. |
Once every server in the estate is classified this way, keep the classification with the change record. That record is what an auditor or incident responder will ask for if exploitation is later reported.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

