Critical Check Point Management Server Flaw (CVE-2026-91843) Lets Unauthenticated Attackers Run Code as Root
Critical Check Point Management Server Flaw (CVE-2026-91843) (TL-2026-2557) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-18. It has no confirmed attribution, affects Check Point Software Technologies Quantum Security Management Server /, references 1 CVE (CVE-2026-91843), maps to 10 MITRE ATT&CK techniques (T1046, T1190, T1213), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-2557
- Threat ID
- TL-2026-2557
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-09-18
- Last reviewed
- 2026-09-18
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- health, government administration, financial services, critical infrastructure, technology
- Target regions
- Global, united kingdom
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in Critical Check Point Management Server Flaw (CVE-2026-91843)
Malware and tooling: SmartConsole
An unauthenticated stack-based buffer overflow (CVE-2026-91843, CVSS 9.8, CWE-121) in the login process of Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server lets a remote attacker send an oversized username to gain root code execution before authentication completes. Check Point shipped a LivePatch fix for supported branches; End-of-Support branches (R81.10, R81, R80.x) have no fix.
How Critical Check Point Management Server Flaw (CVE-2026-91843) works
On September 16, 2026, Check Point Software Technologies disclosed CVE-2026-91843 via security advisory sk1000155 and a companion community 'Action required' notification: a stack overflow (CWE-121) triggered during the unauthenticated login process of its Quantum Security Management line. The vulnerable code path is reached through the 'Trusted Clients' setting, which governs which hosts may open a management connection before credentials are ever validated. By submitting a login request carrying an excessively long username, a remote, unauthenticated attacker can overflow the stack and execute arbitrary code with root privileges on the Security Management Server, Multi-Domain Security Management Server, Log Server, or Multi-Domain Log Server. The vulnerability carries a CVSS v3.1 score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) -- network-reachable, low complexity, no privileges or user interaction required, and total impact to confidentiality, integrity, and availability.
Affected releases span the actively supported line -- R82.20 (all Jumbo Hotfix takes, no protection yet at disclosure), R82.10 through Jumbo Hotfix Take 44, R82 through Take 126, and R81.20 through Take 166 -- as well as End-of-Support branches R81.10 (through Take 190), R81, and the entire R80.x family, none of which receive a fix under normal support. Check Point's cloud-hosted Smart-1 Cloud offering is not affected; the vendor had already deployed the fix server-side. Remediation is delivered as LivePatch bundles (BUNDLE_URGENT_SECURITY_UPDATE): Take 29 for R82.20 and Take 28 for R82.10, R82, and R81.20, installable automatically via the automatic-updates channel or manually, with installation verified using the 'cplp list' command. Organizations on End-of-Support branches must open a support ticket for a fix or migrate to a supported release. As an interim compensating control, Check Point recommends restricting 'Trusted Clients' (SmartConsole > Manage & Settings > Permissions & Administrators > Trusted Clients) to specific administrator IP addresses rather than 'Any,' and hunting SmartConsole/audit logs for the signature 'Administrator failed to log in: Username too long,' which indicates an attempted overflow trigger.
As of publication (September 16-17, 2026) there is no confirmed in-the-wild exploitation and no public proof-of-concept; CISA records the exploitation status as 'none' and has not added CVE-2026-91843 to its Known Exploited Vulnerabilities catalog. However, Censys's internet-exposure advisory identified 3,836 globally distributed hosts presenting the default Check Point Security Internal Communication (SIC) identity 'cp_mgmt' used to fingerprint management-server roles -- a total role-presence count, not a confirmed-vulnerable count, but one that illustrates the scale of internet-facing exposure. Censys characterized the risk bluntly: a pre-auth RCE against network security management infrastructure tends to get weaponized fast once a working trigger is published. Because a Security Management Server holds full network topology, security policy, and third-party/directory/cloud integration credentials for every gateway it manages, per Check Point's own gateway-and-management hardening guidance, compromise of this single component would give an attacker the ability to view topology and stored credentials, and to push modified policy to every managed gateway -- including disabling enforcement or permitting unauthorized traffic.
CVE-2026-91843 is the fifth critical, unauthenticated Check Point management-plane vulnerability disclosed since July 2026, following CVE-2026-16232 (SmartConsole authentication bypass, actively exploited, added to CISA KEV July 22, 2026), CVE-2026-62144 (management-server authentication bypass enabling administrative command execution, disclosed the same day), CVE-2026-18574 (authentication bypass enabling command execution, disclosed August 3, 2026), and CVE-2026-85103 (heap overflow in VPN certificate decoding reaching Quantum Security Management, disclosed September 9, 2026) -- indicating a sustained pattern of attacker and researcher attention on Check Point's management infrastructure.
MITRE ATT&CK techniques used in TL-2026-2557
Discovery
T1046 Network Service Discovery
Initial Access
T1190 Exploit Public-Facing Application
Collection
T1213 Data from Information Repositories
Impact
T1489 Service Stop; T1499.004 Application or System Exploitation
Credential Access
Resource Development
Reconnaissance
T1592.002 Software; T1595.002 Vulnerability Scanning
defense-impairment
Affected products and versions in Critical Check Point Management Server Flaw (CVE-2026-91843)
- Check Point Software Technologies — Quantum Security Management Server / Multi-Domain Security Management Server / Log Server / Multi-Domain Log Server
Vulnerable versions: R82.20 (all Jumbo Hotfix Takes); R82.10 (Jumbo Hotfix Take 44 or below); R82 (Jumbo Hotfix Take 126 or below); R81.20 (Jumbo Hotfix Take 166 or below); R81.10 (Jumbo Hotfix Take 190 or below, End of Support); R81 (End of Support); R80.40 (End of Support); R80.30 (End of Support); R80.20 (End of Support); R80.10 (End of Support)
Fixed in: R82.20 with LivePatch Take 29; R82.10 with LivePatch Take 28; R82 with LivePatch Take 28; R81.20 with LivePatch Take 28 - Check Point Software Technologies — Smart-1 Cloud
Fixed in: Fix already deployed server-side by the vendor; not affected
Remediation for Critical Check Point Management Server Flaw (CVE-2026-91843)
Patches
- LivePatch BUNDLE_URGENT_SECURITY_UPDATE Take 29 for R82.20
- LivePatch BUNDLE_URGENT_SECURITY_UPDATE Take 28 for R82.10
- LivePatch BUNDLE_URGENT_SECURITY_UPDATE Take 28 for R82
- LivePatch BUNDLE_URGENT_SECURITY_UPDATE Take 28 for R81.20
- End-of-Support branches (R81.10, R81, R80.40, R80.30, R80.20, R80.10, R80): fix obtainable only via a Check Point support ticket
Immediate actions
- Apply Check Point LivePatch BUNDLE_URGENT_SECURITY_UPDATE immediately on every Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server (R82.20 Take 29; R82.10/R82/R81.20 Take 28), or confirm the automatic-updates channel already applied it
- Restrict SmartConsole 'Trusted Clients' (Manage & Settings > Permissions & Administrators > Trusted Clients) to specific known administrator IP addresses instead of 'Any' as a compensating control
- Hunt SmartConsole and audit logs for the entry 'Administrator failed to log in: Username too long,' which indicates an attempted exploitation trigger
- Verify installed patch level on every instance with the 'cplp list' command
Workarounds
- Restrict Trusted Clients to specific known administrator source IPs rather than 'Any'
- Monitor for the 'Administrator failed to log in: Username too long' audit-log signature as a detection proxy pending patching
Longer-term hardening
- Plan migration off End-of-Support branches (R81.10, R81, R80.40, R80.30, R80.20, R80.10, R80), which receive no vendor fix for this flaw under normal support
- Reduce internet exposure of Check Point management-plane interfaces (SIC/CPMI) identified via internet-scanning services such as Censys
- Enable the Check Point automatic-updates channel to receive future LivePatch fixes without manual intervention
- Review and rotate third-party, directory-service, and cloud-platform integration credentials stored on the Security Management Server given its central role over all managed gateways
CVEs associated with Critical Check Point Management Server Flaw (CVE-2026-91843)
Weaknesses (CWE) in Critical Check Point Management Server Flaw (CVE-2026-91843)
CWE-121
Timeline of Critical Check Point Management Server Flaw (CVE-2026-91843)
- Check Point discloses CVE-2026-16232 (SmartConsole authentication bypass, CVSS 9.1-9.3) and CVE-2026-62144 (management-server authentication bypass enabling administrative command execution); CISA adds CVE-2026-16232 to its KEV catalog the same day, confirming active exploitation -- the first entries in the 2026 pattern of critical unauthenticated Check Point management-plane flaws.
- Check Point discloses CVE-2026-18574, an authentication bypass enabling command execution on the management server -- the third flaw in the 2026 pattern.
- Check Point discloses CVE-2026-85103, a heap overflow in VPN certificate decoding reaching Quantum Security Management -- the fourth flaw in the 2026 pattern.
- The Hacker News publishes coverage of CVE-2026-91843, noting it is the fifth critical unauthenticated Check Point management flaw disclosed since July 2026.
- Check Point publishes advisory sk1000155 and a community 'Action required' notification disclosing CVE-2026-91843 (CVSS 9.8), providing LivePatch fixes for R82.20, R82.10, R82, and R81.20.
- Additional security-media coverage (SecurityOnline, Cybersecurity News, threat.wiki) republishes technical detail and hunting guidance, emphasizing the 'Administrator failed to log in: Username too long' audit-log detection signature.
- NHS Digital issues UK healthcare-sector cyber alert cc-4854 referencing CVE-2026-91843.
- Censys publishes an advisory identifying 3,836 internet-exposed hosts globally presenting the Check Point 'cp_mgmt' Security Internal Communication identity (total role presence, not a confirmed-vulnerable count).
- CISA records the exploitation status of CVE-2026-91843 as 'none'; the CVE has not been added to the CISA Known Exploited Vulnerabilities catalog and no public proof-of-concept exists as of this date.
Sources cited for Critical Check Point Management Server Flaw (CVE-2026-91843)
- Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
- Check Point advisory sk1000155
- CVE-2026-91843 CVE Record
- NVD CVE-2026-91843 Detail
- [Important Notification] Action required - Critical Security Update (CVE-2026-91843)
- Sept. 16 Advisory: Check Point Quantum Security Management and Log Server Unauthenticated Login Stack Overflow [CVE-2026-91843]
- CVE-2026-91843: Quantum Security Management Stack Buffer Overflow
- Check Point Vulnerability Lets Remote Hackers Gain Root Access Without Authentication
- Critical Check Point Login Flaw Enables Remote Takeover
- Check Point Security Management Server CVE-2026-91843: unauthenticated stack overflow in the login process
- NHS Digital cyber alert cc-4854 (CVE-2026-91843)
More in vulnerability
- cPanel/WHM CalDAV/CardDAV and WP Toolkit Flaws Enable Cross-Account Access and Root Privilege Escalation (CVE-2026-68490, CVE-2026-87899, CVE-2026-87900)
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for Unauthenticated Remote Code Execution
- Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)
- ConfigConfusion: Missing Authorization Check in GCP Config Connector Lets a Kubernetes Namespace User Seize Organization Owner
- OAuth Token Theft via Sideloaded AppX Packages Abusing Microsoft-Signed Web Hosts (WWAHost.exe)
Detection coverage for TL-2026-2557
As of 2026-09-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2557 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.