Check Point has released fixes for CVE-2026-91843, a critical stack-overflow vulnerability in the unauthenticated login process used by Security Management and Log Servers. The vendor assigned the issue a CVSS score of 9.8 and warned that successful exploitation could allow remote arbitrary-code execution with root privileges.
The flaw affects self-managed management infrastructure
Check Point lists Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server among the affected products. Smart-1 Cloud is not affected because the fix was applied within the hosted environment. Censys researchers said the vulnerable path can be reached with an oversized username in a login request and documented the internet-visible management-server footprint without treating every observed host as confirmed vulnerable.
Apply the vendor fix and limit trusted access
Check Point provides a LivePatch and fixed Jumbo Hotfix Accumulator takes for supported branches. Administrators should follow the vendor advisory for their exact release, verify the patch state, and restrict management access to trusted systems. Public reporting said no exploitation was known at disclosure, so the risk should not be described as an active campaign without new evidence. The severity instead comes from the pre-authentication path and potential root-level impact. Additional vulnerability coverage is organized in the SectechMedia Technology News archive.

Leave a Reply