Check Point Software has released security updates to address a critical vulnerability in the login process of Security Management Servers, the systems that manage Security Gateways, including firewalls, and monitor network security events. The vulnerability is tracked as CVE-2026-91843 and could allow attackers with no prior privileges to remotely execute code with root privileges.
The issue is a stack-based buffer overflow in the login path. According to the published details, the attack can be carried out with low complexity and without any user interaction, increasing its operational risk in environments that rely on these servers as a central point for managing security and monitoring logs.
Affected Systems and Nature of the Risk
The vulnerability is not limited to Security Management Server; it also affects Log Server, a server designed to collect and store logs generated by Check Point firewalls. The company warned that all Security Management Server deployments are at risk, regardless of the management settings used, and that the presence of the vulnerability does not depend on whether VPN is enabled or configured.
Successful exploitation gives an attacker the ability to execute code remotely on the system with root privileges. This does not mean that every system has been compromised, but it makes addressing the flaw a priority for teams responsible for management and log servers, because these systems are directly connected to operations for controlling network security components.
Update and Temporary Mitigation
Check Point has provided security fixes and also made LivePatch available for systems that can apply it. For customers unable to install the latest LivePatch immediately, the company recommended hardening systems exposed to attack and restricting access to trusted IP addresses or subnets only.
This restriction is configured through Manage & Settings > Permissions & Administrators > Trusted Clients in the SmartConsole interface. These measures remain temporary mitigations and are not a substitute for applying the available security fixes.
Monitoring Indicator and Broader Context
Check Point did not say that CVE-2026-91843 was being actively exploited in attacks as of the publication date. Security teams can search audit logs and administrator login records for the alert: Administrator failed to log in: Username too long, as a potential indicator of attempts to exploit the vulnerability.
The warning follows the patching of two other critical vulnerabilities in the previous week. The first, CVE-2026-85103, is associated with a heap-based buffer overflow in the VPN certificate decoding path using ASN.1, while CVE-2026-85102 allows authentication bypass and remote code execution on affected firewalls. Check Point also noted other vulnerabilities that had been actively exploited in recent months, including CVE-2026-50751 and CVE-2026-16232.
Why Does This Matter?
The practical risk is not tied to an isolated peripheral service, but to the management and logging layer that organizations rely on to operate their security gateways and monitor their events. Accordingly, the priority is to identify affected systems, apply the fix or LivePatch, temporarily restrict access sources, and then review logs for the stated indicator. At the same time, the source does not establish that the new vulnerability has been exploited, nor does it provide the affected version numbers or timelines for the availability of each fix; these are points that require direct verification against Check Point’s security bulletin before final operational decisions are made.