Check Point patched CVE-2026-91843, a critical stack overflow (CVSS 9.8) in the login process of its Security Management and Log Servers, that lets an unauthenticated attacker execute code as root simply by sending a login request with an extremely long username. The flaw sits before authentication happens at all, and Check Point’s advisory says the attack path only works when a customer has enabled the Trusted Clients setting, which governs access to the management server through SmartConsole. Affected releases span current and end-of-support versions alike, from R82.20 down through R81.10 Jumbo Hotfix Take 190, plus the fully end-of-support R80 and R81 lines. The fix ships through Check Point’s LivePatch channel; customers with automatic updates already have it, while everyone else needs to apply the update described in advisory sk1000155. As of disclosure, Check Point said it had no indication of in-the-wild exploitation.
The scanning firm Censys, credited with the discovery, separately found 3,836 internet-facing hosts globally carrying the Security Management or Log Server role, identified by the default Security Internal Communication identity Check Point assigns those servers, though Censys noted it cannot determine which of those hosts are actually patched since build and Jumbo Hotfix level are not visible in passive scan data.
The reason this rates above a routine patch cycle is what these servers actually are: the control plane that manages firewall policy and holds the logs across a customer’s entire Check Point gateway fleet. A root-level, pre-authentication compromise there does not just take down one box, it hands an attacker the ability to alter the same firewall rules and log records an incident responder would use to detect that alteration, the same log-integrity problem CyberTech has previously flagged in unauthenticated root-RCE flaws in identity and access infrastructure. Organizations still running an end-of-support R80.x branch have no patch available at all, only migration, which is worth escalating now rather than at the next refresh cycle. CyberTech covered a related pair of critical, unauthenticated Check Point VPN flaws earlier this year.
Source: Check Point