Check Point released an urgent security update addressing a critical Check Point login flaw. The vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges. Administrators must install the released LivePatch hotfix immediately to protect enterprise networks.
- CVE: CVE-2026-91843
- CVSS: 9.8 (Critical · CVSSv3)
- Product: checkpoint Quantum Security Management
- Affected: R82.10 with Jumbo Hotfix Take 44 or below, R82 with Jumbo Hotfix Take 126 or below, R81.20 with Jumbo Hotfix Take 166 or below, R81.10 (EOS) with Jumbo Hotfix Take 190 or below, R81 (EOS), R80.40 (EOS) (+4 more)
- Impact: Stack overflow in login process to the Security Management and Log Servers
- Status: No confirmed exploitation yet
- Action: See vendor advisory
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy This Threat Matters
Thousands of global organizations use Check Point management servers to control corporate firewalls. Consequently, flaws in these central platforms expose entire network perimeters to hostile takeovers. If attackers compromise a management server, they can alter security policies. Furthermore, intruders can pivot across internal networks and disable active defenses.
How the Attack Works
The vulnerability carries a critical CVSS base score of 9.8. The advisory warns: “A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.” To trigger the bug, an attacker sends oversized input during the initial authentication sequence. As a result, this invalid input triggers a stack buffer overflow in the login service.
Additionally, administrators can identify potential attack attempts inside SmartConsole logs. Specifically, defenders should search for audit messages reading “Administrator failed to log in: Username too long.” Check Point confirmed that no public exploit code or in-the-wild attacks exist currently.
Affected Versions
This Check Point login flaw impacts multiple software releases. The vulnerability affects Security Management Server and Multi-Domain Security Management Server deployments. It also impacts Log Server and Multi-Domain Log Server systems. Affected releases include R82.20, R82.10, R82, R81.20, and earlier unsupported versions. However, the vendor confirmed that Smart-1 Cloud instances are not affected.
Patch and Mitigation Steps
Administrators should deploy the latest Check Point LivePatch package without delay. Systems with enabled automatic updates receive the fix automatically. You can find detailed upgrade instructions in the official Check Point security advisory. If administrators cannot patch immediately, they should restrict trusted GUI clients to dedicated internal IP subnets. Finally, teams should never set the trusted client type to accept any remote address.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!