Check Point Fixes Critical Management Server Flaw Allowing Root Code Execution

This digest was compiled by AI from multiple sources — links to the originals are below.
Check Point has released a fix for a critical vulnerability in its Security Management and Log Servers that could let unauthenticated attackers run code as root. The flaw, CVE-2026-91843, rated 9.8 on the CVSS scale, is a stack overflow in the login process. Check Point says it has no indication the flaw has been exploited.
Key Facts
- CVE-2026-91843 is rated 9.8 out of 10 on the CVSS scale by Check Point.
- The flaw is a stack overflow in the login process, triggered by a login request with a very long username.
- Check Point released the fix through its LivePatch update channel and advisory sk1000155.
- CISA recorded exploitation as 'none' in its assessment attached to the CVE record on September 17, 2026.
- Affected branches include R82.10 with Jumbo Hotfix Take 44 or below, R82 with Take 126 or below, R81.20 with Take 166 or below, and R81.10 with Take 190 or below.
Vulnerability Details
The vulnerability is a stack overflow in the login process, which handles requests before a user is authenticated. Internet scanning company Censys said the overflow is triggered by a login request that carries a very long username. Check Point told The Hacker News that the vulnerable path runs only through the Trusted Clients setting, which controls which hosts may connect to the management server through SmartConsole. The flaw allows an unauthenticated attacker to remotely execute arbitrary code with root privileges through the login process.
Affected Versions and Fix
Check Point's CVE record lists affected branches by Jumbo Hotfix Take, including R82.10 with Take 44 or below, R82 with Take 126 or below, R81.20 with Take 166 or below, and R81.10 with Take 190 or below. R81, R80.40, R80.30, R80.20, R80.10 and R80 are all end of support and affected. Aviv Abramovich, vice president of product management for network security at Check Point, said R82.20 is also vulnerable, and Censys said every R82.20 build is affected with no Jumbo Hotfix yet protecting that branch. Standalone deployments, Log Servers and Multi-Domain servers are also vulnerable, Abramovich said. Check Point said customers with automatic updates enabled are already protected, and everyone else should apply the LivePatch fix described in advisory sk1000155.
Exploitation Status
Check Point said in its CheckMates notice on September 16, 2026, that there is no indication the vulnerability has been exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recorded exploitation as 'none' in its assessment attached to the CVE record on September 17. The flaw was not in CISA's Known Exploited Vulnerabilities catalog as of the catalog's September 16 release. Censys said no public proof-of-concept exploit existed as of September 16. Check Point has shared some potential indicators of compromise (IoCs) with customers.