Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2916+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. New Check Point Flaw Lets Hackers Execute Code With Root Privileges
New Check Point Flaw Lets Hackers Execute Code With Root Privileges
NEWS

New Check Point Flaw Lets Hackers Execute Code With Root Privileges

An unauthenticated stack overflow in Check Point's Security Management Server login process allows root-level remote code execution. CVSS 9.8.

Dylan H.

News Desk

September 19, 2026
3 min read

An Overlong Username, a Root Shell

Check Point has patched a critical stack-based buffer overflow, tracked as CVE-2026-91843 (CVSS 9.8), in the unauthenticated login process of its Security Management Server and Log Server — including the Multi-Domain variants of both. A remote attacker who sends a crafted login request with an excessively long username can trigger the overflow and execute arbitrary code as root, before authentication ever completes and without needing any credentials or user interaction.

Security Management Server is the system administrators use to push firewall policy, oversee Security Gateways, and monitor security events across a Check Point deployment. Check Point's own framing of the risk is blunt: an attacker who compromises the management server effectively owns every gateway, every policy, and every rule it controls.


Vulnerability Details

AttributeValue
CVE IDCVE-2026-91843
CWECWE-121 (Stack-Based Buffer Overflow)
CVSS Score9.8 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected ProductsSecurity Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server
DisclosedSeptember 16, 2026
DiscoveryFound internally by Check Point; no reported exploitation

Check Point states all Security Management Server deployments are vulnerable regardless of configuration, and the flaw is present even when VPN is not in use or configured — there's no feature-based way to opt out of exposure short of patching.

This is the fifth critical management-plane vulnerability Check Point has disclosed in its product line in under eight weeks.


Remediation

Check Point ships the fix via LivePatch rather than a standalone build:

TrackFixed Take
R82.20Take 29
R82.10Take 28
R82Take 28
R81.20Take 28

Systems with automatic updates enabled per sk175504 receive the fix automatically. Where LivePatch can't be deployed immediately, Check Point recommends:

  • Restricting SmartConsole access to trusted IP addresses/subnets (Manage & Settings → Permissions & Administrators → Trusted Clients)
  • General hardening of exposed management systems

Detection

Administrators can watch the Audit and Admin login logs for the alert "Administrator failed to log in: Username too long" — a signature of attempted exploitation of the overflow.

Check Point reports no confirmed in-the-wild exploitation as of publication, and the CVE is not yet listed in CISA's Known Exploited Vulnerabilities catalog. Given the low attack complexity and lack of authentication required, organizations running exposed Security Management Server or Log Server instances should treat patching as urgent rather than wait for confirmed exploitation.

Sources

  • BleepingComputer — New Check Point Flaw Lets Hackers Execute Code With Root Privileges
#Vulnerability#Check Point#Security Updates#Buffer Overflow

Related Articles

Critical Check Point Flaw Lets Unauthenticated Attackers Run Code as Root

A CVSS 9.8 stack overflow in Check Point's Security Management Server allows unauthenticated root RCE; Kaspersky and Tanium also patch flaws this week.

3 min read

Check Point Patches Critical VPN Vulnerabilities

CVE-2026-85102 and CVE-2026-85103 (CVSS 9.8) let attackers achieve unauthenticated RCE via Check Point VPN certificate handling.

7 min read

CVE-2026-16232: Check Point SmartConsole Improper Authentication

A critical improper authentication flaw in Check Point SmartConsole allows unauthenticated remote attackers to steal login tokens and gain full admin...

5 min read
Back to all News