CHECK Point has fixed CVE-2026-91843, a critical vulnerability with a CVSS score of 9.8 affecting its Security Management and Log Servers. The flaw could allow an unauthenticated attacker to execute arbitrary code with root privileges over the network. According to Censys researchers, the issue is a stack overflow in the pre-authentication login process, triggered by sending a login request containing an extremely long username.
Check Point said the attack path works only when the Trusted Clients setting is enabled, controlling access to the management server through SmartConsole.
Affected releases include R82.20; R82.10 Jumbo Hotfix Take 44 or earlier; R82 Jumbo Hotfix Take 126 or earlier; R81.20 Jumbo Hotfix Take 166 or earlier; and R81.10 Jumbo Hotfix Take 190 or earlier. Older, end-of-support releases including R80 through R81 are also affected. Check Point distributed the fix through its LivePatch channel, so customers with automatic updates enabled should already be protected.
Others should apply the update detailed in advisory sk1000155 and restrict Trusted Clients access to known internal IP addresses. Check Point said there was no indication of exploitation in the wild, while Censys reported no public proof-of-concept exploit as of 16 September 2026. Censys identified 3,836 hosts globally carrying the relevant server role, but stressed that this is not a confirmed count of vulnerable systems.