Check Point Says Every Security Management Server Is Open to Unauthenticated Root Attacks
Check Point sk1000155 (16 September 2026) covers CVE-2026-91843, a CVSS 9.8 stack overflow in the unauthenticated login path on Security Management and Log Servers. The fix is LivePatch Take 29 on R82.20 and Take 28 on R82.10, R82, and R81.20. Smart-1 Cloud is not affected.

Check Point published SecureKnowledge advisory sk1000155 for CVE-2026-91843, dated 16 September 2026. The vendor page describes a stack overflow in the unauthenticated login process on Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server. It assigns a CVSS score of 9.8.
This is a vendor security advisory and LivePatch guidance. It is not a report that this CVE is already in active use, and it is not the same bug as last week's VPN certificate flaws.
BleepingComputer (Sergiu Gatlan, 18 September 2026) says a successful attack gives unauthenticated remote code execution as root, with low complexity and no user interaction. BleepingComputer quoted Check Point saying all Security Management Server deployments are vulnerable regardless of configuration, including when VPN is not in use. Smart-1 Cloud is listed as not affected because the fix is already in that environment.
The official fix is Check Point LivePatch Take 29 or later for R82.20, and LivePatch Take 28 or later for R82.10, R82, and R81.20. End-of-support R81.x and R80.x branches are told to move to a supported release. After install, Expert mode cplp list should show fwm armed for CVE-2026-91843.
Until the take lands, Check Point's temporary mitigation is to restrict Trusted Clients in SmartConsole (Manage and Settings, Permissions and Administrators, Trusted Clients) to trusted IPs or subnets, and not leave Client Type set to Any. Detection in Audit and Admin login logs is the string "Administrator failed to log in: Username too long."
Check Point has not flagged CVE-2026-91843 as actively exploited. Do not mix it with CVE-2026-85102 and CVE-2026-85103, or with earlier auth-bypass zero-days that Qilin abused. Those are different bugs.
Related management-plane tape includes Cisco Secure FMC under active attack and MikroTik SSH abuse already in the wild.
If you run an on-prem Check Point management or log server that is not Smart-1 Cloud, apply LivePatch Take 29 on R82.20 or Take 28 on R82.10, R82, and R81.20 today, then confirm cplp list shows CVE-2026-91843 armed.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free