<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Log Server (&lt; R81.20 Take 28, &lt; R82 Take 28, &lt; R82.10 Take 28, &lt; R82.20 Take 29) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/log-server--r81.20-take-28--r82-take-28--r82.10-take-28--r82.20-take-29/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 17 Sep 2026 13:08:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/log-server--r81.20-take-28--r82-take-28--r82.10-take-28--r82.20-take-29/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution Vulnerability in Check Point Management Products</title><link>https://feed.craftedsignal.io/briefs/2026-09-checkpoint-rce/</link><pubDate>Thu, 17 Sep 2026 13:08:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-checkpoint-rce/</guid><description>A critical remote code execution vulnerability (CVE-2026-91843) affects multiple Check Point security management servers, allowing unauthenticated attackers to execute arbitrary code.</description><content:encoded><![CDATA[<p>On September 16, 2026, Check Point released security advisory sk1000155 addressing a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-91843. The vulnerability affects various Security Management and Log Server deployments, including Multi-Domain environments. Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the affected appliance. Defenders should audit logs for specific indicators of failed authentication attempts associated with username length anomalies.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-91843 results in total system compromise, enabling attackers to gain control over security management infrastructure, access sensitive logs, and potentially pivot into the protected network segments managed by the affected Check Point gateways. Organizations using Security Management Servers or Log Servers are at risk of complete administrative takeover.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch all affected Check Point Security Management and Log Server instances by upgrading to the minimum version requirements specified in the vendor advisory (e.g., R81.20 take 28, R82 take 28, R82.10 take 28, or R82.20 take 29).</li>
<li>Perform a retrospective audit of SmartConsole Audit and Admin login logs to identify the string &quot;Administrator failed to log in: Username too long&quot;, which may indicate reconnaissance or exploitation attempts.</li>
<li>Ensure all administrative management interfaces are restricted to trusted, segmented management networks and not exposed to the public internet.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>network-security</category></item></channel></rss>