Check Point has issued security updates for CVE-2026-91843, a critical stack-based buffer overflow that lets unauthenticated attackers execute code as root on Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server deployments. With no user interaction required and low attack complexity, UK firms need to implement robust vulnerability management and patch without delay.
View the data behind this chart
| R82.10 | R82 | R81.20 | R81.10 | |
|---|---|---|---|---|
| Vulnerable HF Take | Take #44 | Take #126 | Take #166 | Take #190 |
What Check Point disclosed about CVE-2026-91843
The flaw sits in the login process for Security Management Server instances — the systems that administer Security Gateways (firewalls) and monitor network security events — and also affects Check Point's dedicated Log Server, which stores logs from Check Point firewalls.
Because the bug is a stack-based buffer overflow triggered before authentication, an attacker with no credentials at all can achieve remote code execution as root, in a low-complexity attack that needs no user interaction. Check Point has not flagged the flaw as actively exploited, and it told The Hacker News it has seen no indication of exploitation so far. Security teams can look for a specific tell: an "Administrator failed to log in: Username too long" alert in the Audit and Admin login logs.
Which branches and builds are affected
Vulnerable builds span major Check Point branches including R82.10 Jumbo Hotfix Take 44 or below, R82 Jumbo Hotfix Take 126 or below, R81.20 Jumbo Hotfix Take 166 or below, and R81.10 Jumbo Hotfix Take 190 or below. Some of these, such as R81.10, are end-of-support. R81, R80.40, R80.30, R80.20, R80.10 and R80 are end of support, so customers should not expect routine fixes and should plan migration.
Estates still on those retired versions face a harder decision: migrate the management plane now, or lean on enhance support with third-party maintenance to keep the hardware serviceable while a replacement project is scoped and funded.
Why this lands amid a brutal 2026 patch cycle for Check Point
This disclosure follows a torrid run of Check Point vulnerabilities this year. Recently, the vendor patched two other critical flaws: CVE-2026-85103, a heap overflow in the VPN certificate ASN.1 decoding flow affecting firewalls and management systems, and CVE-2026-85102, an authentication bypass that lets unauthenticated attackers execute code remotely on vulnerable firewalls. Check Point's advisory, as quoted by BleepingComputer, stated that "all Security Management Server deployments are vulnerable, regardless of configuration," even when VPN is not in use.
That warning matters because it echoes a pattern seen twice already this year. A June authentication bypass zero-day, CVE-2026-50751, was abused by threat actors associated with the Qilin ransomware operation, and a July authentication bypass zero-day, CVE-2026-16232, has been exploited since at least that month to gain administrator access to SmartConsole panels. The Dutch NCSC has since urged organisations to prioritise the September VPN flaws, warning it expects exploitation to occur soon. For internet-facing management infrastructure, that turnaround from disclosure to weaponisation has been measured in weeks, not months — a case study for anyone building an understand attack surface management programme around administrative interfaces.

Immediate mitigation steps for UK security teams
Check Point's remediation path is a LivePatch fix documented under sk1000155, applied to every Security Management Server and Log Server in the estate. Where that can't be rolled out immediately, the vendor's temporary measures focus on cutting off the exploitation path rather than the code itself.
- •Apply the LivePatch fix referenced in sk1000155 to all affected Security Management Server and Log Server instances
- •Restrict Trusted Clients under Manage & Settings > Permissions & Administrators > Trusted Clients in SmartConsole to known, trusted IP addresses or subnets
- •Ensure, in line with vendor guidance, that the management server is not directly exposed to the public internet wherever possible
- •Watch Audit and Admin login logs for the "Administrator failed to log in: Username too long" signature
Procurement and architecture lessons for UK buyers
The recurring theme across this year's Check Point disclosures is that the management plane, not just the gateway, is now the primary target. Buyers should treat the Security Management Server as a crown-jewel asset and apply the same segmentation discipline they would to a domain controller — a strong case for extending zero trust principles to administrative access rather than relying solely on perimeter controls. Given the pace of critical CVEs against a single vendor's management stack this year, some estates may also want to review vendor concentration risk and evaluate a second supported platform, such as options within consider Fortinet firewall solutions, for new deployments or DR sites.
Bottom line for UK infrastructure buyers
Check Point has said it has no evidence of active exploitation of CVE-2026-91843 as of the latest advisory, but that status can change fast given this year's track record with Check Point auth-bypass and RCE flaws. Patch via sk1000155 now, lock down Trusted Clients as a stopgap, and treat any Security Management Server or Log Server still on an end-of-support branch as an urgent migration item.
- 01BleepingComputer — New Check Point flaw lets hackers execute code with root privileges · 18 September 2026
- 02The Hacker News — Critical Check Point management server flaw disclosed · 18 September 2026
- 03BleepingComputer — Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent · 11 September 2026
- 04BleepingComputer — Check Point patches SmartConsole zero-day exploited in attacks · 15 July 2026
- 05BleepingComputer — CISA orders feds to patch Check Point flaw exploited by ransomware gangs · 20 June 2026
- 06The Hacker News — Critical Check Point VPN flaw exploited · 5 June 2026
- 07The Hacker News — Rapid7 releases PoC for exploited Check Point flaw · 16 July 2026
