Summary
Check Point has patched CVE-2026-91843, a critical stack-based buffer overflow vulnerability in the login process of its Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server products that allows unauthenticated remote attackers to execute arbitrary code with root privileges. The vulnerability is rated CVSS 9.8 and affects all Security Management Server deployments regardless of configuration. An attacker triggers the buffer overflow by sending a login request with an excessively long username field — the overflow occurs before authentication completes, requiring no credentials. Check Point has released a fix through its LivePatch update channel and states it has no indication the vulnerability has been exploited in the wild as of September 19. CISA has assessed exploitation as “none” in its initial recording. This is the third critical Check Point vulnerability disclosed within one week, following CVE-2026-85102 and CVE-2026-85103 (TTO-2026-0913-123).
Timeline
| Date | Event |
|---|---|
| Sep 16, 2026 | Check Point posts advisory sk1000155 on CheckMates community; customers with automatic updates already protected via LivePatch |
| Sep 17, 2026 | Check Point releases formal security notice; CISA records CVE-2026-91843 with exploitation status: none; Censys confirms buffer overflow trigger via long username |
| Sep 18-19, 2026 | BleepingComputer, The Hacker News, and additional outlets report full technical details; TTO-2026-0919-144 published |
What Happened
CVE-2026-91843 is a stack-based buffer overflow in the login workflow of Check Point’s Security Management Server family. The login process handles incoming authentication requests before verifying credentials. When an attacker submits a login request with an excessively long username field, the server’s handling of that input triggers a stack overflow. Because the overflow occurs in a pre-authentication code path, no valid credentials are required. Internet scanning by Censys confirmed that a login request carrying a very long username is the triggering condition.
The Security Management Server is the administrative control plane for Check Point firewall deployments — the system that controls firewall policy, administrator access, and log collection across an organization’s entire Check Point deployment. Root code execution on the management server gives an attacker complete visibility into network security policy, administrator credentials, audit logs, and the ability to modify firewall rules across the entire protected environment.
Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server running R82.20, R82.10 with Jumbo Hotfix Take 44 or earlier, R82 with Jumbo Hotfix Take 126 or earlier, and R81.20 with Jumbo Hotfix Take 166 or earlier. Check Point Smart-1 Cloud customers are unaffected. Administrators who cannot immediately apply the LivePatch fix should restrict SmartConsole access to trusted IP subnets via Manage & Settings > Permissions & Administrators > Trusted Clients. Defenders can detect exploitation attempts by monitoring for “Administrator failed to log in: Username too long” alerts in audit and admin login logs.
Domain Intelligence
checkpoint.com — 87.0
Score unchanged from TTO-2026-0913-123. checkpoint.com scores at 87.0, in the high-trust range. Check Point is the vendor of the affected Security Management Server product and the party that patched CVE-2026-91843 and published remediation guidance. This is the third critical vulnerability in Check Point products disclosed within one week.
The Trust Observatory · thetrustobservatory.com · September 19, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026