TTO-2026-0922-150 · September 22, 2026 Active ExploitationFollow-Up

Check Point Security Management Server CVE-2026-91843 Now Actively Exploited — Updates TTO-2026-0919-144

checkpoint.comCVE-2026-91843 CVSS 9.8Active exploitation confirmedStack overflow in login processUnauthenticated root RCEUpdates TTO-2026-0919-144

Summary

Check Point has confirmed that CVE-2026-91843, the critical stack-based buffer overflow vulnerability in its Security Management Server documented in TTO-2026-0919-144 as having no known active exploitation, is now being actively exploited in attacks. Check Point published an updated advisory on September 21-22, 2026 confirming exploitation in the wild and urging immediate application of the LivePatch fix. CISA has updated its KEV entry for CVE-2026-91843 to reflect active exploitation. This bulletin records the change in exploitation status and upgrades the urgency classification accordingly.

Timeline

DateEvent
Sep 16, 2026Check Point patches CVE-2026-91843 via LivePatch; no exploitation reported at time of patch
Sep 19, 2026TTO-2026-0919-144 published; exploitation status: none per CISA initial assessment
Sep 21-22, 2026Check Point confirms active exploitation in attacks; CISA updates KEV entry; Check Point urges immediate LivePatch application

What Changed

TTO-2026-0919-144 documented CVE-2026-91843 as a critical unauthenticated stack overflow in the login process of Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server, with no active exploitation reported at time of publication and a LivePatch fix available.

Active exploitation has now been confirmed. Administrators who applied the LivePatch fix before exploitation began should verify that the patch applied successfully and audit admin login logs for “Administrator failed to log in: Username too long” events. Administrators who have not yet applied the LivePatch fix should treat this as an emergency remediation. As a temporary measure, restrict SmartConsole access to trusted IP subnets via Manage & Settings > Permissions & Administrators > Trusted Clients. Check Point Smart-1 Cloud customers remain unaffected. This is the fourth critical Check Point vulnerability confirmed actively exploited in September 2026.

Domain Intelligence

checkpoint.com — 87.0

Score unchanged from TTO-2026-0919-144. checkpoint.com scores at 87.0 in the high-trust range. Check Point is the vendor of the affected Security Management Server product.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 22, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026