2026-09-18 · view entry permalink →
CVE-2026-91843, Check Point Security Management / Multi-Domain Security Management / Log Server: unauthenticated stack overflow in the login process reaches root RCE (CVSS 9.8)
Check Point disclosed CVE-2026-91843 (CVSS 9.8) on 2026-09-16: a stack-based buffer overflow in the unauthenticated login process to Check Point Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server lets an attacker who reaches the login interface send an oversized username to overflow the stack and execute arbitrary code as root, without valid credentials or user interaction (Check Point PSIRT, 2026-09-16). No source (Check Point's own advisory, BSI CERT-Bund, or CERT-FR) reports observed exploitation (Check Point PSIRT, 2026-09-16; CERT-FR CERTFR-2026-AVI-1193, 2026-09-17). Check Point ships the fix as a LivePatch rather than a full upgrade: administrators with automatic updates enabled per sk175504 are already protected, and cplp list in Expert mode should show the CVE-2026-91843 patch armed on affected R82.20, R82.10, R82 and R81.20 builds; R81.10 and earlier R80.x/R81 lines are past end-of-support and remain unpatched (Check Point PSIRT, 2026-09-16). The management login service should not normally be internet-facing, but any organization that exposes it, directly or via an overlooked NAT or VPN path, is a single unauthenticated request away from root on the box that holds every firewall policy and credential in the fleet, which is why this clears the bar for action despite no confirmed exploitation.
Triage: Check Point's own SmartConsole Audit/Admin login log entry "Administrator failed to log in: Username too long" is the exploitation-attempt signature; a genuine failed login records a normal username-length failure, so this specific message text appearing where no legitimate oversized-username attempt occurred is the discriminator (Check Point PSIRT, 2026-09-16).
A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
In SmartConsole, search for Audit and Admin login logs containing the message: "Administrator failed to log in: Username too long".