FR
live
tag

#check-point

Check Point patches a login stack overflow that grants unauthenticated root on management servers

On September 17, 2026, Check Point shipped an emergency fix for CVE-2026-91843, a CVSS 9.8 stack overflow in the login process of its management and log servers that lets an unauthenticated attacker run code as root. Apply the Live Patch to every instance, confirm it with cplp list, and tighten Trusted Clients before someone takes over your firewall’s management plane.

Check Point patches two CVSS 9.8 flaws in its VPN certificate handling

On September 9, 2026, Check Point fixed two CVSS 9.8 flaws in how its firewalls and management console validate and decode VPN certificates, both exploitable without authentication for remote code execution. The Dutch NCSC says exploitation is imminent: apply the Live Patch or the Jumbo Hotfix now.

Ransomware Surges 48% in May 2026 as Global Attacks Decline

Check Point Research records 698 ransomware attacks worldwide in May 2026, a 48% year-over-year jump, even as overall attack volumes drop 7%. Fewer attacks, more impact — threat actors are getting better at doing more with less.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss