TTO-2026-0919-144 · September 19, 2026 CriticalVulnerability

Check Point Security Management Server CVE-2026-91843 CVSS 9.8 Stack Overflow Allows Unauthenticated Root RCE — No Active Exploitation Reported

checkpoint.comCVE-2026-91843 CVSS 9.8Stack-based buffer overflow in login processUnauthenticated root RCESecurity Management Server / Log Server / Multi-Domain variantsNo active exploitation as of Sep 19LivePatch fix availableThird Check Point critical in one week

Summary

Check Point has patched CVE-2026-91843, a critical stack-based buffer overflow vulnerability in the login process of its Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server products that allows unauthenticated remote attackers to execute arbitrary code with root privileges. The vulnerability is rated CVSS 9.8 and affects all Security Management Server deployments regardless of configuration. An attacker triggers the buffer overflow by sending a login request with an excessively long username field — the overflow occurs before authentication completes, requiring no credentials. Check Point has released a fix through its LivePatch update channel and states it has no indication the vulnerability has been exploited in the wild as of September 19. CISA has assessed exploitation as “none” in its initial recording. This is the third critical Check Point vulnerability disclosed within one week, following CVE-2026-85102 and CVE-2026-85103 (TTO-2026-0913-123).

Timeline

DateEvent
Sep 16, 2026Check Point posts advisory sk1000155 on CheckMates community; customers with automatic updates already protected via LivePatch
Sep 17, 2026Check Point releases formal security notice; CISA records CVE-2026-91843 with exploitation status: none; Censys confirms buffer overflow trigger via long username
Sep 18-19, 2026BleepingComputer, The Hacker News, and additional outlets report full technical details; TTO-2026-0919-144 published

What Happened

CVE-2026-91843 is a stack-based buffer overflow in the login workflow of Check Point’s Security Management Server family. The login process handles incoming authentication requests before verifying credentials. When an attacker submits a login request with an excessively long username field, the server’s handling of that input triggers a stack overflow. Because the overflow occurs in a pre-authentication code path, no valid credentials are required. Internet scanning by Censys confirmed that a login request carrying a very long username is the triggering condition.

The Security Management Server is the administrative control plane for Check Point firewall deployments — the system that controls firewall policy, administrator access, and log collection across an organization’s entire Check Point deployment. Root code execution on the management server gives an attacker complete visibility into network security policy, administrator credentials, audit logs, and the ability to modify firewall rules across the entire protected environment.

Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server running R82.20, R82.10 with Jumbo Hotfix Take 44 or earlier, R82 with Jumbo Hotfix Take 126 or earlier, and R81.20 with Jumbo Hotfix Take 166 or earlier. Check Point Smart-1 Cloud customers are unaffected. Administrators who cannot immediately apply the LivePatch fix should restrict SmartConsole access to trusted IP subnets via Manage & Settings > Permissions & Administrators > Trusted Clients. Defenders can detect exploitation attempts by monitoring for “Administrator failed to log in: Username too long” alerts in audit and admin login logs.

Domain Intelligence

checkpoint.com — 87.0

Score unchanged from TTO-2026-0913-123. checkpoint.com scores at 87.0, in the high-trust range. Check Point is the vendor of the affected Security Management Server product and the party that patched CVE-2026-91843 and published remediation guidance. This is the third critical vulnerability in Check Point products disclosed within one week.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 19, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026