CTIPilot

Check Point Security Management/Multi-Domain Security Management/Log Server unauthenticated stack overflow in login process to root RCE (CVSS 9.8), no confirmed exploitation, LivePatch fix

cve · CVE-2026-91843

Coverage timeline
1
first 2026-09-18 → last 2026-09-18
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
4
see Co-occurring entities below
ATT&CK techniques
1
pinned v19.2 · see below

ATT&CK techniques

1 technique observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-18/cve-2026-91843-check-point-security-mgmt-stack-overflow · ATT&CK page ↗

Story timeline

  1. 2026-09-18CVE-2026-91843, Check Point Security Management / Multi-Domain Security Management / Log Server: unauthenticated stack overflow in the login process reaches root RCE (CVSS 9.8)
    trending-vulnerabilitiesAn oversized username in Check Point's management login reaches root, patch or restrict management-plane access now

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • cert.ssi.gouv.fr1 (33%)
  • support.checkpoint.com1 (33%)
  • wid.cert-bund.de1 (33%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Check Point Security Management/Multi-Domain Security Management/Log Server unauthenticated stack overflow in login process to root RCE (CVSS 9.8), no confirmed exploitation, LivePatch fix (1)

2026-09-18 · view entry permalink →

HIGHCVE-2026-91843NATOA2

CVE-2026-91843, Check Point Security Management / Multi-Domain Security Management / Log Server: unauthenticated stack overflow in the login process reaches root RCE (CVSS 9.8)

Check Point disclosed CVE-2026-91843 (CVSS 9.8) on 2026-09-16: a stack-based buffer overflow in the unauthenticated login process to Check Point Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server lets an attacker who reaches the login interface send an oversized username to overflow the stack and execute arbitrary code as root, without valid credentials or user interaction (Check Point PSIRT, 2026-09-16). No source (Check Point's own advisory, BSI CERT-Bund, or CERT-FR) reports observed exploitation (Check Point PSIRT, 2026-09-16; CERT-FR CERTFR-2026-AVI-1193, 2026-09-17). Check Point ships the fix as a LivePatch rather than a full upgrade: administrators with automatic updates enabled per sk175504 are already protected, and cplp list in Expert mode should show the CVE-2026-91843 patch armed on affected R82.20, R82.10, R82 and R81.20 builds; R81.10 and earlier R80.x/R81 lines are past end-of-support and remain unpatched (Check Point PSIRT, 2026-09-16). The management login service should not normally be internet-facing, but any organization that exposes it, directly or via an overlooked NAT or VPN path, is a single unauthenticated request away from root on the box that holds every firewall policy and credential in the fleet, which is why this clears the bar for action despite no confirmed exploitation.

Triage: Check Point's own SmartConsole Audit/Admin login log entry "Administrator failed to log in: Username too long" is the exploitation-attempt signature; a genuine failed login records a normal username-length failure, so this specific message text appearing where no legitimate oversized-username attempt occurred is the discriminator (Check Point PSIRT, 2026-09-16).

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

In SmartConsole, search for Audit and Admin login logs containing the message: "Administrator failed to log in: Username too long".

Check Point PSIRT (sk1000155) 2026-09-16
vulnerability18 Sep 04:50Zmulti-sourceOpen finding ↗