The box that pushes your firewall policy has a critical unauthenticated stack overflow in the login path. Check Point Security Management / Log servers can be driven to root code execution before a user ever authenticates — if an attacker can reach them through Trusted Clients.
Vendor says no known exploitation yet. Severity says do not wait for the first public PoC to become your change ticket.
What happened
On September 16, 2026, Check Point disclosed CVE-2026-91843 (CVSS 9.8): a stack overflow in the pre-authentication login process, triggerable with an oversized username. Successful exploitation yields remote root code execution on Security Management, Multi-Domain Management, Log, and Multi-Domain Log Servers — including standalone management+gateway deployments. Hosted Smart-1 Cloud is already fixed.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
The vulnerable path runs through the Trusted Clients setting (which hosts may talk to the management server via SmartConsole). Check Point ships an urgent LivePatch via sk1000155. CISA’s CVE assessment recorded exploitation as none at disclosure; the bug was not on the Sep 16 KEV batch — treat it as a management-plane emergency anyway.
Why it matters
Root on the management server means policy rewrite, administrator takeover, and trust collapse across every gateway that server controls. This is the latest in a string of critical unauthenticated Check Point management-plane flaws since July.
“Automatic updates enabled” is not the same as “LivePatch landed.” Prior urgent packages have rolled out in stages — verify with cplp list.
What to do first
- Apply the LivePatch from sk1000155 to every Security Management and Log Server. Confirm with
cplp listthat the patch is installed and armed. - Restrict Trusted Clients to known admin hosts — never “Any” / unrestricted. Do not expose management directly to the internet; require VPN.
- If auto-update is on, still verify the LivePatch arrived; do not assume.
- EoS branches (R81.10 and older listed as end-of-support): open a Check Point support ticket for the backported fix, or migrate.
- R82.20: treat as affected per vendor confirmation even where Jumbo tables lag — follow sk1000155.
Details
- CVE: CVE-2026-91843 (CVSS 9.8)
- Class: Unauthenticated stack overflow in login process → root RCE
- Products: Security Management, Multi-Domain Management, Log / Multi-Domain Log, standalone
- Not affected: Smart-1 Cloud (fix already applied)
- Reachability: Via Trusted Clients path
- Fix: LivePatch sk1000155; Jumbo Hotfix Takes vary by branch (see vendor CVE / sk)
- Exploitation (vendor/CISA at disclosure): None indicated
Hunt / verify
- Run
cplp listand confirm the LivePatch for this issue is present. - Audit Trusted Clients for Any / unexpected IPs; review recent SmartConsole logins and admin account changes.
- Watch management-plane logs for oversized username / anomalous pre-auth login attempts.
Sources
- Check Point sk1000155 — LivePatch guidance
- The Hacker News: Check Point management root RCE (CVE-2026-91843)
- NVD: CVE-2026-91843
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.