Check Point has issued an urgent security update for CVE-2026-91843, a critical buffer overflow vulnerability that could allow a remote attacker to run code with root-level privileges without logging in.
The vulnerability has a CVSS score of 9.8, making it a high-priority issue. It can be exploited remotely without user interaction or existing privileges.
The problem occurs during the login process. An attacker can submit an unusually long username, causing a stack overflow before authentication is completed.
If successfully exploited, the attacker could gain complete control of the affected system and potentially access management information, security policies, administrator details, and stored logs.
Affected Check Point Products
The vulnerability affects several Check Point management and logging products, including:
- Security Management Server
- Multi-Domain Security Management Server
- Log Server
- Multi-Domain Log Server
Affected releases include R82.20, older builds of R82.10, R82, R81.20, and unsupported R81.10, R80, R80.40, and R81 versions.
Check Point says Smart-1 Cloud is not affected, as the fix has already been applied to that environment.
Check Point has not reported active exploitation or publicly disclosed technical details of an exploit.
What Security Teams Should Do
Organizations should treat this vulnerability as an urgent patching priority.
Security teams should check SmartConsole Audit and Admin login records for:
“Administrator failed to log in: Username too long.”
This could indicate an attempted exploit, but the surrounding activity should be reviewed before confirming compromise.
Check Point has distributed the fix through Check Point LivePatch. Organizations using automatic security updates should still verify that the patch is active on every affected management and logging server.
Administrators can check the LivePatch status from Expert mode using:
cplp list
The affected systems should show the fwm patch as armed and running in livepatch mode, with CVE-2026-91843 listed in the patch details.
Until patching is confirmed, organizations should also limit SmartConsole Trusted Clients to known and approved IP addresses or subnets.
Because this vulnerability can provide root access without authentication, organizations should prioritize exposed and unsupported Check Point management systems and move to supported releases as part of remediation.