Check Point has released a security update for a critical vulnerability in its Security Management and Log Servers that could allow an unauthenticated attacker to execute code with root privileges over the network.

The vulnerability, tracked as CVE-2026-91843 and rated 9.8 out of 10 on the CVSS severity scale, affects the login process on vulnerable servers. The flaw is a stack overflow that can be triggered before authentication by sending a login request containing an unusually long username.

The affected Security Management Server manages firewall policies and administrator access. Check Point has released a fix through its LivePatch update channel and said it does not indicate that the vulnerability has been exploited in the wild.

According to Check Point, the vulnerable attack path is accessible only through the Trusted Clients setting, which determines which hosts can connect to the management server through SmartConsole. The company is urging customers to apply the security update immediately because of the vulnerability’s severity and potential impact.

Customers with automatic updates enabled should already have received the LivePatch fix, while others are advised to apply the update described in Check Point security advisory sk1000155. Check Point said on September 16 that there was no evidence of exploitation. CISA also recorded no known exploitation when it assessed the CVE record on September 17.

Check Point’s listed affected versions include R82.10 with Jumbo Hotfix Take 44 or earlier, R82 with Take 126 or earlier, and R81.20 with Take 166 or earlier. R81.10 is affected through Take 190, while older R81, R80.40, R80.30, R80.20, R80.10 and R80 branches are also vulnerable but have reached end of support.

READ
Hackers Hijack HBO Max Reddit Account to Push Malware Ads

The R82.20 branch is not listed in Check Point’s CVE record, but Check Point’s vice president of product management for network security said it is also vulnerable. Censys reported that every R82.20 build is affected and that a Jumbo Hotfix was not yet available for that branch at the time of its advisory.

Standalone deployments, where the management server and gateway operate on the same system, as well as Log Servers and Multi-Domain Servers, are also affected. The hosted Smart-1 Cloud service is not vulnerable because the required fix has already been applied.

Administrators should apply the LivePatch update to every affected Security Management Server and Log Server. Even when automatic updates are enabled, Check Point recommends verifying that the patch has actually been installed. The cplp list command can be used to check installed LivePatches and their status.

Administrators should also review the Trusted Clients configuration and make sure management access is restricted to known and trusted hosts. Check Point recommends avoiding direct exposure of management interfaces to the internet and ensuring that Trusted Clients is not configured to allow connections from any IP address.

Censys said it identified 3,836 hosts worldwide presenting the default identity associated with Check Point management and log servers. However, the company stressed that this number represents systems identified as running the relevant server roles and should not be interpreted as the number of confirmed vulnerable systems.

READ
Critical WordPress Plugin Flaws Put 600,000 Websites at Risk

CVE-2026-91843 is also the fifth critical vulnerability since July 22 that could be reached without authentication on Check Point Security Management Server, according to The Hacker News’ review of Check Point’s CVE records.

The first of these, CVE-2026-16232, was an authentication bypass that Check Point said had been exploited in July. Another management-server authentication bypass, CVE-2026-62144, was disclosed at the same time but was not reported as exploited.

Two additional vulnerabilities followed. CVE-2026-18574, disclosed on August 3, was an authentication bypass that could lead to command execution on the management server. CVE-2026-85103, disclosed on September 9, was a heap overflow in VPN certificate decoding that could also affect Quantum Security Management. Check Point said it discovered both vulnerabilities internally and had no evidence that they had been exploited.

The identity of the researcher who discovered CVE-2026-91843 has not been disclosed, and Check Point did not provide details about who originally reported the vulnerability.


Buy ExpressVPN with PayPal or Credit Card

Advertisement