GBHackers

Critical Check Point Vulnerability Allows Remote Root Code Execution Without Authentication


Check Point has issued a high-severity security alert for CVE-2026-91843, which is a critical stack overflow vulnerability in the login process of its Security Management and Log Server products.

This flaw could allow an unauthenticated remote attacker to execute arbitrary code with root privileges, posing a significant risk to organizations utilizing affected Check Point management infrastructure.

Check Point Vulnerability

This issue is tracked under solution ID sk1000155 and has received a CVSS score of 9.8 out of 10. The vulnerability affects the unauthenticated login workflow, meaning an attacker may not require valid administrative credentials to exploit it. Successful exploitation could grant an attacker root-level execution on the targeted management or log server.

The affected products include Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server deployments.

Vulnerable releases comprise R82.20, R82.10 systems running Jumbo Hotfix Take 44 or earlier, R82 systems with Jumbo Hotfix Take 126 or earlier, and R81.20 installations using Jumbo Hotfix Take 166 or earlier.

Additionally, older releases such as R81.10 with Jumbo Hotfix Take 190 or earlier, along with R80, R80.10, R80.20, R80.30, R80.40, and R81, are also exposed.

Check Point has marked several of these versions as end of support. Organizations still using unsupported versions should treat this issue as especially urgent, as they may lack a straightforward supported upgrade path beyond applying available remediation measures.

Check Point Smart-1 Cloud customers are not affected, as the fix has already been implemented in that environment.

Administrators can identify potential exploitation attempts by reviewing SmartConsole audit logs and administrator login logs. Check Point recommends searching for entries containing the following message:

“Administrator failed to log in: Username too long”

This log entry may indicate that a remote entity submitted an unusually long username, which could be associated with attempts to trigger the vulnerable stack overflow condition.

However, investigate this event in context, as it may also represent failed or malformed login attempts. Security teams should examine affected systems for suspicious administrator login activity, unexpected changes to management configurations, unauthorized accounts, unexplained process activity, and possible indicators of root-level compromise.

Check Point has released a LivePatch to address this vulnerability. Organizations that have enabled automatic updates in line with Check Point’s guidance are automatically protected.

The vendor recommends deploying this update across all Security Management Servers, Multi-Domain Security Management Servers, and Log Servers.

For manual offline deployment, Check Point provides urgent security update bundles for R82.20, R82.10, R82, and R81.20 environments. The relevant package takes are as follows:

  • R82.20: Take 29
  • R82.10: Take 28
  • R82: Take 28
  • R81.20: Take 28

After applying the patch, administrators can validate the deployment in Expert mode using the following command:

cplp list

The expected output should show “fwm:fwm” as armed in live patch mode, along with a comment referencing CVE-2026-91843.

As an additional security measure, Check Point advises restricting SmartConsole Trusted Clients to approved IP addresses or subnets. Administrators should avoid configuring the Client Type as “Any,” limiting access to management interfaces solely to trusted administrative workstations and networks.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link