Description
A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
Published: 2026-09-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a stack overflow that occurs during the unauthenticated login phase of Checkpoint's Quantum Security Management and Log Servers. Exploitation allows a remote attacker to execute arbitrary code with root privileges. The flaw is a stack‑based buffer overflow (CWE‑121).

Affected Systems

Checkpoint Quantum Security Management servers that handle security policy management and log data are affected. No specific version range is listed in the CVE; any system that uses the vulnerable login process may be exposed.

Risk and Exploitability

The CVSS score of 9.8 signifies critical impact, while the EPSS score of < 1% suggests that observed exploitation activity is currently minimal. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed public exploitation. Based on the description, the flaw occurs during the unauthenticated login process, so the likely attack vector is remote over the network via malicious authentication data sent to the login endpoint; this could trigger the stack overflow and allow arbitrary code execution with root privileges. Given the severity, organizations should treat the exposure as a high‑priority risk.

Generated by OpenCVE AI on September 18, 2026 at 07:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or update for the Quantum Security Management login module to eliminate the stack overflow flaw.
  • Restrict external access to the login service by implementing firewall rules or VPN‑only policies so that only trusted networks can reach the affected endpoints.
  • Continuously monitor authentication logs for abnormal login attempts and investigate any anomalies promptly to detect potential exploit attempts.

Generated by OpenCVE AI on September 18, 2026 at 07:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Checkpoint
Checkpoint quantum Security Management
Vendors & Products Checkpoint
Checkpoint quantum Security Management

Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
Title Stack overflow in login process to the Security Management and Log Servers
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Checkpoint Quantum Security Management
cve-icon MITRE

Status: PUBLISHED

Assigner: checkpoint

Published:

Updated: 2026-09-17T11:39:25.299Z

Reserved: 2026-09-15T08:30:18.206Z

Link: CVE-2026-91843

cve-icon Vulnrichment

Updated: 2026-09-17T11:32:25.433Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:13.947

Modified: 2026-09-18T19:34:36.657

Link: CVE-2026-91843

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow