Check Point security advisory (AV26-933)
At a glance
- Severity
- CriticalCVSS 9.8
- Used in attacks
- Not on CISA’s list
- Flaws named
- CVE-2026-91843
- Reported by
- 1 outlet
As of September 16, 2026, Check Point is affected by a vulnerability in the following products:
- Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server
- R81.20 with Jumbo Hotfix Take 166 and prior
- R82 with Jumbo Hotfix Take 126 and prior
- R82.10 with Jumbo Hotfix Take 44 and prior
- R82.20
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Originally published by Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
Vulnerabilities referenced
- CVE-2026-918439.8Critical
Product not named yet
A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
Full record →
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-17 18:21 UTC
Related stories
- Apple patches CoreGraphics zero-day flaw exploited in attacks
BleepingComputer · 2026-09-29
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The Hacker News · 2026-09-29
- OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
The Hacker News · 2026-09-29
- One Packet Can Crash OT Servers in Industrial Sectors
Dark Reading · 2026-09-28