A significant vulnerability has been identified in Check Point's Security Management and Log Servers, allowing attackers to execute code as root without requiring login credentials. This flaw, known as CVE-2026-91843, has received a critical severity rating of 9.8 on the CVSS scale. It arises from a stack overflow in the login process, which can be triggered by a login request with an excessively long username.
Check Point has responded by issuing a fix via their LivePatch update channel, ensuring that systems with automatic updates enabled are already protected. The issue specifically impacts those configurations where the Trusted Clients setting permits connections to the management server via SmartConsole. Customers who have not enabled automatic updates should urgently apply the LivePatch fix referenced in advisory sk1000155.
Despite the severity of the vulnerability, there is no current evidence of exploitation in the wild as confirmed by both Check Point and the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The flaw has not been added to CISA's Known Exploited Vulnerabilities catalog, and no public proof-of-concept exploit has been reported.
The affected branches, including R82.20, standalone deployments, Log Servers, and Multi-Domain servers, must be addressed with appropriate fixes. Systems on older or unsupported versions can obtain a fix by contacting Check Point support. Check Point advises customers to restrict the Trusted Clients setting to specific trusted hosts to minimize exposure.
Censys has identified thousands of hosts worldwide running Check Point's management and log servers, but these numbers reflect role presence, not confirmed vulnerabilities. Previous issues with the Security Management Server underline the importance of securing internet-exposed management systems and limiting access to trusted IP addresses.

