• PoC PUBLIC

CVE-2026-91843: pre-auth remote code execution in Check Point Quantum Security Management

An unauthenticated remote attacker can trigger a stack overflow in Check Point Quantum Security Management and execute arbitrary code as root. CVE-2026-91843 affects many released branches of Quantum Security Management including R82.10 with Jumbo Hotfix Take 44 or below, R82 with Jumbo Hotfix Take 126 or below, R81.20 with Jumbo Hotfix Take 166 or below, several R81/R80.x EOS releases and other listed builds. The flaw occurs during the login process and requires only network access to the management interface; no user interaction or valid credentials are needed.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00519
CWE
CWE-121
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as urgent: public exploit code exists for a remotely triggerable, unauthenticated root code execution bug against an internet-facing management product. Immediately reduce exposure and follow vendor guidance.

What is CVE-2026-91843?

An unauthenticated remote attacker can trigger a stack overflow in Check Point Quantum Security Management and execute arbitrary code as root. CVE-2026-91843 affects many released branches of Quantum Security Management including R82.10 with Jumbo Hotfix Take 44 or below, R82 with Jumbo Hotfix Take 126 or below, R81.20 with Jumbo Hotfix Take 166 or below, several R81/R80.x EOS releases and other listed builds. The flaw occurs during the login process and requires only network access to the management interface; no user interaction or valid credentials are needed.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Check Point Quantum Security Management are affected?

BRANCHAFFECTEDFIXED
Quantum Security ManagementR82.10 with Jumbo Hotfix Take 44 or below
Quantum Security ManagementR82 with Jumbo Hotfix Take 126 or below
Quantum Security ManagementR81.20 with Jumbo Hotfix Take 166 or below
Quantum Security ManagementR81.10 (EOS) with Jumbo Hotfix Take 190 or below
Quantum Security ManagementR81 (EOS)
Quantum Security ManagementR80.40 (EOS)
Quantum Security ManagementR80.30 (EOS)
Quantum Security ManagementR80.20 (EOS)
Quantum Security ManagementR80.10 (EOS)
Quantum Security ManagementR80 (EOS)

Is CVE-2026-91843 being exploited?

Public exploit code is available.

How to fix CVE-2026-91843

  1. Restrict access to Quantum Security Management interfaces to trusted management networks or VPN only.
  2. Apply vendor guidance and hardening recommendations for management servers immediately.
  3. Monitor management server logs and IDS/IPS for exploitation attempts and anomalous process activity.
  4. Prepare to install vendor patches as soon as fixed releases are published and schedule expedited testing.

Frequently asked questions

Is CVE-2026-91843 being actively exploited?

Public exploit code is available for CVE-2026-91843 against Check Point Quantum Security Management, which increases the risk of active exploitation.

Which Quantum Security Management versions are affected by CVE-2026-91843?

Quantum Security Management versions listed as affected include R82.10 with Jumbo Hotfix Take 44 or below; R82 with Jumbo Hotfix Take 126 or below; R81.20 with Jumbo Hotfix Take 166 or below; R81.10 (EOS) with Jumbo Hotfix Take 190 or below; and several R81 and R80.x EOS releases shown in the vendor listing.

Is there a patch for CVE-2026-91843?

No fixed versions are listed in the affected data; follow Check Point guidance and apply vendor patches when they become available.

Does CVE-2026-91843 require authentication?

No, the vulnerability occurs during the unauthenticated login process and does not require valid credentials to exploit.

References