Check Point security advisory (AV26-933)

CriticalCVSS 9.8Canadian Centre for Cyber Security · Canadian Centre for Cyber Security·

At a glance

Severity
CriticalCVSS 9.8
Used in attacks
Not on CISA’s list
Flaws named
CVE-2026-91843
Reported by
1 outlet

As of September 16, 2026, Check Point is affected by a vulnerability in the following products:

  • Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server
    • R81.20 with Jumbo Hotfix Take 166 and prior
    • R82 with Jumbo Hotfix Take 126 and prior
    • R82.10 with Jumbo Hotfix Take 44 and prior
    • R82.20

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Originally published by Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.

Vulnerabilities referenced

  • CVE-2026-918439.8Critical

    Product not named yet

    A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

    Full record →

Fastnexa security experts

Dealing with this in your own company?

If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →

Coverage

One outlet has carried this so far.

  1. Canadian Centre for Cyber Security ↗Official SourceFirst reported

    2026-09-17 18:21 UTC

Related stories

Check Point security advisory (AV26-933) | CyberBrief