Critical Check Point Vulnerability Allows Remote Root Code Execution Without Authentication
Check Point patched CVE-2026-91843 (CVSS 9.8), an unauthenticated stack overflow enabling remote root code execution on Security Management and Log Servers.
Check Point issued a high-severity alert for CVE-2026-91843, a critical stack overflow (CVSS 9.8, solution sk1000155) in the unauthenticated login workflow of Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server. Successful exploitation grants an unauthenticated remote attacker root-level code execution. Affected releases span R80 through R82.20 with Jumbo Hotfix takes at or below specified levels (e.g., R82.20 Take 44, R81.20 Take 166), with several older versions end of support. A LivePatch is available and offline urgent bundles (R81.20-R82.20 Takes 28-29) were released; Smart-1 Cloud is already protected.
- Unauthenticated stack overflow in login process allows remote root code execution, CVSS 9.8
- Affects Security Management, Multi-Domain, and Log Servers from R80 to R82.20 on older Jumbo Hotfix takes
- LivePatch released; auto-update customers protected, offline bundles available for R81.20-R82.20
- Hunt for 'Administrator failed to log in: Username too long' log entries as possible exploitation indicators
- Restrict SmartConsole Trusted Clients to approved IPs; several affected versions are end of support
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91843 | Unauthenticated stack overflow gives root RCE in Check Point login process CVE-2026-91843 is a stack-based buffer overflow (CWE-121) in the unauthenticated login process of a Check Point product, as Check Point Software ([email protected]) is the assigning CNA and its CVE scope covers Check Point products. An attacker can trigger the flaw remotely by sending crafted input to the login interface before authenticating, with no user interaction or credentials required. Successful exploitation allows arbitrary code execution with root privileges, the highest level of control on the affected system. The vulnerability is rated 9.8 Critical (AV:N/AC:L/PR:N/UI:N, all impacts high), reflecting trivial network exploitability. No public proof-of-concept or confirmed in-the-wild exploitation is known at this time, and the source data does not name the specific product line or affected version ranges. Do: Monitor Check Point's official advisory channels for the affected product/version list and patch release, and upgrade as soon as fixed versions are published. In the interim, restrict the login/management interface of Check Point appliances to trusted management networks and remove any direct internet exposure, and review perimeter logs for anomalous pre-authentication traffic against that interface. | 9.8 | — |
| — |
Full article549 words · extracted from gbhackers.com · click to collapse
Check Point has issued a high-severity security alert for CVE-2026-91843, which is a critical stack overflow vulnerability in the login process of its Security Management and Log Server products.
This flaw could allow an unauthenticated remote attacker to execute arbitrary code with root privileges, posing a significant risk to organizations utilizing affected Check Point management infrastructure.
Check Point Vulnerability
This issue is tracked under solution ID sk1000155 and has received a CVSS score of 9.8 out of 10. The vulnerability affects the unauthenticated login workflow, meaning an attacker may not require valid administrative credentials to exploit it. Successful exploitation could grant an attacker root-level execution on the targeted management or log server.
The affected products include Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server deployments.
Vulnerable releases comprise R82.20, R82.10 systems running Jumbo Hotfix Take 44 or earlier, R82 systems with Jumbo Hotfix Take 126 or earlier, and R81.20 installations using Jumbo Hotfix Take 166 or earlier.
Additionally, older releases such as R81.10 with Jumbo Hotfix Take 190 or earlier, along with R80, R80.10, R80.20, R80.30, R80.40, and R81, are also exposed.
Check Point has marked several of these versions as end of support. Organizations still using unsupported versions should treat this issue as especially urgent, as they may lack a straightforward supported upgrade path beyond applying available remediation measures.
Check Point Smart-1 Cloud customers are not affected, as the fix has already been implemented in that environment.
Administrators can identify potential exploitation attempts by reviewing SmartConsole audit logs and administrator login logs. Check Point recommends searching for entries containing the following message:
“Administrator failed to log in: Username too long”
This log entry may indicate that a remote entity submitted an unusually long username, which could be associated with attempts to trigger the vulnerable stack overflow condition.
However, investigate this event in context, as it may also represent failed or malformed login attempts. Security teams should examine affected systems for suspicious administrator login activity, unexpected changes to management configurations, unauthorized accounts, unexplained process activity, and possible indicators of root-level compromise.
Check Point has released a LivePatch to address this vulnerability. Organizations that have enabled automatic updates in line with Check Point’s guidance are automatically protected.
The vendor recommends deploying this update across all Security Management Servers, Multi-Domain Security Management Servers, and Log Servers.
For manual offline deployment, Check Point provides urgent security update bundles for R82.20, R82.10, R82, and R81.20 environments. The relevant package takes are as follows:
- R82.20: Take 29
- R82.10: Take 28
- R82: Take 28
- R81.20: Take 28
After applying the patch, administrators can validate the deployment in Expert mode using the following command:
cplp list
The expected output should show “fwm:fwm” as armed in live patch mode, along with a comment referencing CVE-2026-91843.
As an additional security measure, Check Point advises restricting SmartConsole Trusted Clients to approved IP addresses or subnets. Administrators should avoid configuring the Client Type as “Any,” limiting access to management interfaces solely to trusted administrative workstations and networks.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/critical-check-point-vulnerability/