---
schema: 1
kind: vulnerability
title: "CVE-2026-91843 — Check Point Security Management / Multi-Domain Security Management / Log Server: unauthenticated stack overflow in the login process reaches root RCE (CVSS 9.8)"
headline: "An oversized username in Check Point's management login reaches root — patch or restrict management-plane access now"
summary: >
  CVE-2026-91843 (CVSS 9.8) is a stack overflow in the unauthenticated login process to Check
  Point Security Management Server, Multi-Domain Security Management Server, Log Server and
  Multi-Domain Log Server; an attacker who reaches the login interface can send an oversized
  username to execute arbitrary code as root, no credentials or interaction required. No source
  reports observed exploitation as of 2026-09-17; Check Point ships the fix as a LivePatch.
discovered_at: "2026-09-18T04:50:00Z"
updated_at: null
event_date: "2026-09-16"
run_id: 2026-09-18T0410Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, rce, pre-auth, patch-available]
regions: [global]
sectors: [public-sector, technology]
entities: []
techniques: [T1190]
affected_products: ["Check Point Security Management Server", "Check Point Multi-Domain Security Management Server", "Check Point Log Server", "Check Point Multi-Domain Log Server"]
cves:
  - id: CVE-2026-91843
    cvss: "9.8"
    epss: null
    type: memory-corruption
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "R82.20; R82.10 up to Jumbo Hotfix Take 44; R82 up to Take 126; R81.20 up to Take 166; R81.10 (EoS) up to Take 190; all R80.x/R81 (EoS) builds"
    fixed: "LivePatch per train (BUNDLE_URGENT_SECURITY_UPDATE): R82.20 take 29, R82.10 take 28, R82 take 28, R81.20 take 28; manual offline packages also available; customers with automatic updates enabled per sk175504 are already protected"
sources:
  - url: "https://support.checkpoint.com/results/sk/sk1000155"
    publisher: "Check Point PSIRT (sk1000155)"
    date: "2026-09-16"
    role: primary
  - url: "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3429"
    publisher: "BSI CERT-Bund (WID-SEC-2026-3429)"
    date: "2026-09-17"
    role: corroborating
  - url: "https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1193/"
    publisher: "CERT-FR (CERTFR-2026-AVI-1193)"
    date: "2026-09-17"
    role: corroborating
closed_sources: []
evidence:
  - quote: "A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges."
    publisher: "Check Point PSIRT (sk1000155)"
  - quote: "In SmartConsole, search for Audit and Admin login logs containing the message: \"Administrator failed to log in: Username too long\"."
    publisher: "Check Point PSIRT (sk1000155)"
verification: multi-source
sourcing_note: >
  No source — Check Point's own advisory, BSI CERT-Bund, or CERT-FR — reports observed
  exploitation; all three are silent on the question rather than carrying an affirmative
  "not exploited" field.
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Apply the CVE-2026-91843 LivePatch (confirm `cplp list` in Expert mode shows it armed) to every Check Point Security Management, Multi-Domain Security Management, Log Server and Multi-Domain Log Server now, and verify no Trusted Client/GUI access to the login interface reaches it from outside the management network."
updates: []
migrated_from: null
---

Check Point disclosed CVE-2026-91843 (CVSS 9.8) on 2026-09-16: a stack-based buffer overflow in the unauthenticated login process to Check Point Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server lets an attacker who reaches the login interface send an oversized username to overflow the stack and execute arbitrary code as root, without valid credentials or user interaction ([Check Point PSIRT, 2026-09-16](https://support.checkpoint.com/results/sk/sk1000155)). No source — Check Point's own advisory, BSI CERT-Bund, or CERT-FR — reports observed exploitation ([Check Point PSIRT, 2026-09-16](https://support.checkpoint.com/results/sk/sk1000155); [CERT-FR CERTFR-2026-AVI-1193, 2026-09-17](https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1193/)). Check Point ships the fix as a LivePatch rather than a full upgrade: administrators with automatic updates enabled per sk175504 are already protected, and `cplp list` in Expert mode should show the CVE-2026-91843 patch armed on affected R82.20, R82.10, R82 and R81.20 builds; R81.10 and earlier R80.x/R81 lines are past end-of-support and remain unpatched ([Check Point PSIRT, 2026-09-16](https://support.checkpoint.com/results/sk/sk1000155)). The management login service should not normally be internet-facing, but any organization that exposes it, directly or via an overlooked NAT or VPN path, is a single unauthenticated request away from root on the box that holds every firewall policy and credential in the fleet, which is why this clears the bar for action despite no confirmed exploitation.

**Defender takeaway:** apply the LivePatch to every Security Management, Multi-Domain Security Management, Log Server and Multi-Domain Log Server now, and independently verify no Trusted Client/GUI access reaches the login interface from outside the management network rather than relying on the assumption it was never exposed.

**Triage:** Check Point's own SmartConsole Audit/Admin login log entry "Administrator failed to log in: Username too long" is the exploitation-attempt signature; a genuine failed login records a normal username-length failure, so this specific message text appearing where no legitimate oversized-username attempt occurred is the discriminator ([Check Point PSIRT, 2026-09-16](https://support.checkpoint.com/results/sk/sk1000155)).
