securityonline.info 16 Sept 2026, 16:07 UTC

Check Point Patches Critical Flaw Allowing Root Access Without Login

Check Point Patches Critical Flaw Allowing Root Access Without Login
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

CHECK Point has released an urgent LivePatch update for CVE-2026-91843, a critical vulnerability in its Security Management and Log Server products. The flaw has a CVSS v3 score of 9.8 and is described as a stack overflow in the unauthenticated login process. An unauthenticated remote attacker could send oversized input during the initial authentication sequence, potentially executing arbitrary code with root privileges.

Affected deployments include Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server systems. Listed affected releases include R82.10 with Jumbo Hotfix Take 44 or earlier, R82 with Take 126 or earlier, R81.20 with Take 166 or earlier, R81.10 with Take 190 or earlier, R81 and R80.40, as well as earlier unsupported versions. The article says R82.20 is also affected, while Smart-1 Cloud instances are not. Check Point has confirmed that there is currently no public exploit code or known exploitation in the wild.

Administrators should install the latest Check Point LivePatch package, although systems with automatic updates enabled receive the fix automatically. Until patching is possible, the vendor’s guidance is to restrict trusted GUI clients to dedicated internal IP subnets and not configure trusted clients to accept connections from any remote address. SmartConsole audit logs can be checked for the message: “Administrator failed to log in: Username too long.”

View full article

Article by CyberSIXT