Critical Check Point Vulnerability (CVE-2026-91843) Grants Root Access via Buffer Overflow
Check Point has released an urgent security patch for CVE-2026-91843, a critical stack-based buffer overflow vulnerability (CVSS 9.8) that allows unauthenticated remote attackers to execute arbitrary code with root privileges on vulnerable systems. The flaw affects Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server during the login process, where an excessively long username can trigger a stack overflow before authentication completes.
Exploitation could grant attackers full OS control, exposing management data, security policies, administrator credentials, and logs, while enabling further compromise of protected environments. Check Point has not disclosed exploit details or confirmed in-the-wild attacks but warns that end-of-support versions (R80–R80.40, R81, R81.10) remain vulnerable, alongside specific releases of R82.20, R82.10, R82, and R81.20 with outdated hotfixes. Smart-1 Cloud is unaffected due to preemptive patching.
Defenders are advised to monitor SmartConsole Audit and Admin logs for failed login attempts with the message “Username too long,” which may indicate exploitation attempts. Check Point has deployed fixes via LivePatch (automatically for enabled systems) and offline packages for affected versions. Administrators must verify protection by running cplp list in Expert mode, ensuring the fwm:fwm patch appears in “armed” status with CVE-2026-91843 referenced.
Until remediation is confirmed, organizations should restrict SmartConsole Trusted Clients to approved IPs and avoid using “Any” as the client type. Check Point emphasizes that migrating to supported branches does not replace patching, as exposed management interfaces pose severe risk.
Source: https://cybersecuritynews.com/check-point-root-access-flaw/
Check Point TPRM report: https://www.rankiteo.com/company/check-point-software-technologies
"id": "che1789583049",
"linkid": "check-point-software-technologies",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Cybersecurity',
'name': 'Check Point',
'type': 'Cybersecurity Company'}],
'attack_vector': 'Remote',
'data_breach': {'personally_identifiable_information': 'Administrator '
'credentials',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Management data, security '
'policies, administrator '
'credentials, logs'},
'description': 'Check Point has released an urgent security patch for '
'CVE-2026-91843, a critical stack-based buffer overflow '
'vulnerability (CVSS 9.8) that allows unauthenticated remote '
'attackers to execute arbitrary code with root privileges on '
'vulnerable systems. The flaw affects Security Management '
'Server, Multi-Domain Security Management Server, Log Server, '
'and Multi-Domain Log Server during the login process, where '
'an excessively long username can trigger a stack overflow '
'before authentication completes. Exploitation could grant '
'attackers full OS control, exposing management data, security '
'policies, administrator credentials, and logs, while enabling '
'further compromise of protected environments.',
'impact': {'data_compromised': 'management data, security policies, '
'administrator credentials, logs',
'identity_theft_risk': 'Administrator credentials',
'operational_impact': 'Full OS control, further compromise of '
'protected environments',
'systems_affected': 'Security Management Server, Multi-Domain '
'Security Management Server, Log Server, '
'Multi-Domain Log Server'},
'post_incident_analysis': {'corrective_actions': 'Apply security patches, '
'restrict access to '
'management interfaces, '
'monitor for exploitation '
'attempts',
'root_causes': 'Stack-based buffer overflow in '
'login process due to excessively '
'long username'},
'recommendations': 'Migrate to supported branches, apply patches immediately, '
'restrict access to management interfaces, monitor logs '
'for exploitation attempts',
'references': [{'source': 'Check Point Security Advisory'}],
'response': {'containment_measures': 'Restrict SmartConsole Trusted Clients '
"to approved IPs, avoid using 'Any' as "
'the client type',
'enhanced_monitoring': 'Monitor SmartConsole Audit and Admin '
'logs for failed login attempts with the '
"message 'Username too long'",
'remediation_measures': 'Deploy fixes via LivePatch or offline '
'packages, verify protection by running '
'`cplp list` in Expert mode'},
'title': 'Critical Check Point Vulnerability (CVE-2026-91843) Grants Root '
'Access via Buffer Overflow',
'type': 'Buffer Overflow',
'vulnerability_exploited': 'CVE-2026-91843'}