UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

Check Point Critical RCE Vulnerability 2026: Act Now

London · Servnet News Desk · IT infrastructure analysis3 min read
Share

Check Point has issued security updates for CVE-2026-91843, a critical stack-based buffer overflow that lets unauthenticated attackers execute code as root on Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server deployments. With no user interaction required and low attack complexity, UK firms need to implement robust vulnerability management and patch without delay.

Vulnerable Jumbo Hotfix Thresholds by Branch
190Take #143Take #95Take #48Take #0Take #44Take #R82.10126Take #R82166Take #R81.20190Take #R81.10Vulnerable HF Take
View the data behind this chart
Vulnerable Jumbo Hotfix Thresholds by Branch
R82.10R82R81.20R81.10
Vulnerable HF TakeTake #44Take #126Take #166Take #190

What Check Point disclosed about CVE-2026-91843

The flaw sits in the login process for Security Management Server instances — the systems that administer Security Gateways (firewalls) and monitor network security events — and also affects Check Point's dedicated Log Server, which stores logs from Check Point firewalls.

Because the bug is a stack-based buffer overflow triggered before authentication, an attacker with no credentials at all can achieve remote code execution as root, in a low-complexity attack that needs no user interaction. Check Point has not flagged the flaw as actively exploited, and it told The Hacker News it has seen no indication of exploitation so far. Security teams can look for a specific tell: an "Administrator failed to log in: Username too long" alert in the Audit and Admin login logs.

Which branches and builds are affected

Vulnerable builds span major Check Point branches including R82.10 Jumbo Hotfix Take 44 or below, R82 Jumbo Hotfix Take 126 or below, R81.20 Jumbo Hotfix Take 166 or below, and R81.10 Jumbo Hotfix Take 190 or below. Some of these, such as R81.10, are end-of-support. R81, R80.40, R80.30, R80.20, R80.10 and R80 are end of support, so customers should not expect routine fixes and should plan migration.

Estates still on those retired versions face a harder decision: migrate the management plane now, or lean on enhance support with third-party maintenance to keep the hardware serviceable while a replacement project is scoped and funded.

Why this lands amid a brutal 2026 patch cycle for Check Point

This disclosure follows a torrid run of Check Point vulnerabilities this year. Recently, the vendor patched two other critical flaws: CVE-2026-85103, a heap overflow in the VPN certificate ASN.1 decoding flow affecting firewalls and management systems, and CVE-2026-85102, an authentication bypass that lets unauthenticated attackers execute code remotely on vulnerable firewalls. Check Point's advisory, as quoted by BleepingComputer, stated that "all Security Management Server deployments are vulnerable, regardless of configuration," even when VPN is not in use.

That warning matters because it echoes a pattern seen twice already this year. A June authentication bypass zero-day, CVE-2026-50751, was abused by threat actors associated with the Qilin ransomware operation, and a July authentication bypass zero-day, CVE-2026-16232, has been exploited since at least that month to gain administrator access to SmartConsole panels. The Dutch NCSC has since urged organisations to prioritise the September VPN flaws, warning it expects exploitation to occur soon. For internet-facing management infrastructure, that turnaround from disclosure to weaponisation has been measured in weeks, not months — a case study for anyone building an understand attack surface management programme around administrative interfaces.

Illustration: Check Point Critical RCE Vulnerability 2026: Act Now

Immediate mitigation steps for UK security teams

Check Point's remediation path is a LivePatch fix documented under sk1000155, applied to every Security Management Server and Log Server in the estate. Where that can't be rolled out immediately, the vendor's temporary measures focus on cutting off the exploitation path rather than the code itself.

  • Apply the LivePatch fix referenced in sk1000155 to all affected Security Management Server and Log Server instances
  • Restrict Trusted Clients under Manage & Settings > Permissions & Administrators > Trusted Clients in SmartConsole to known, trusted IP addresses or subnets
  • Ensure, in line with vendor guidance, that the management server is not directly exposed to the public internet wherever possible
  • Watch Audit and Admin login logs for the "Administrator failed to log in: Username too long" signature

Procurement and architecture lessons for UK buyers

The recurring theme across this year's Check Point disclosures is that the management plane, not just the gateway, is now the primary target. Buyers should treat the Security Management Server as a crown-jewel asset and apply the same segmentation discipline they would to a domain controller — a strong case for extending zero trust principles to administrative access rather than relying solely on perimeter controls. Given the pace of critical CVEs against a single vendor's management stack this year, some estates may also want to review vendor concentration risk and evaluate a second supported platform, such as options within consider Fortinet firewall solutions, for new deployments or DR sites.

Bottom line for UK infrastructure buyers

Check Point has said it has no evidence of active exploitation of CVE-2026-91843 as of the latest advisory, but that status can change fast given this year's track record with Check Point auth-bypass and RCE flaws. Patch via sk1000155 now, lock down Trusted Clients as a stopgap, and treat any Security Management Server or Log Server still on an end-of-support branch as an urgent migration item.

Share
Key takeaways
  • CVE-2026-91843 is a critical, unauthenticated root RCE in Check Point Security Management Server and Log Server login handling — patch via sk1000155 immediately.
  • Not yet confirmed as exploited, but Check Point's 2026 record (Qilin ransomware, SmartConsole bypass) shows fast weaponisation of similar flaws.
  • Restrict SmartConsole Trusted Clients and confirm management servers aren't internet-facing as an interim mitigation.
  • R81, R80.40, R80.30, R80.20, R80.10 and R80 are end of support with no fix — migrate these branches now.
Frequently asked

FAQs — Check Point Critical RCE Vulnerability 2026

What is CVE-2026-91843?

It's a critical stack-based buffer overflow in the login process for Check Point Security Management Server and Log Server, allowing attackers without any credentials to execute code as root remotely, without user interaction.

Is CVE-2026-91843 being actively exploited?

Check Point has not flagged it as exploited and told researchers it has no indication of attacks so far, though this could change given the vendor's recent history of exploited flaws.

Which Check Point versions need patching?

R82.10 Jumbo Hotfix Take 44 or below, R82 Take 126 or below, R81.20 Take 166 or below, and R81.10 Take 190 or below are vulnerable; R81 and R80.x branches are end of support with no fix, so implement robust vulnerability management to track and remediate them.

What if we can't apply the LivePatch immediately?

Restrict SmartConsole's Trusted Clients setting to known IP addresses or subnets, ensure the management server isn't exposed to the internet, and monitor Audit and Admin login logs for the documented failed-login signature.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111