Check Point Software has issued patches addressing a critical vulnerability affecting its management infrastructure. The flaw, identified as CVE-2026-91843, originates from a stack-based buffer overflow present in the authentication mechanism of Security Management Server deployments, which oversee Security Gateways and track network security activity.
The vulnerability extends to Check Point's Log Server product, which aggregates and maintains log data from Check Point firewalls. Attackers lacking valid credentials can achieve root-level remote code execution through low-complexity attacks that require no user participation.
For organizations unable to deploy the latest LivePatch immediately, Check Point recommends interim protective steps. These include strengthening system defenses and restricting access to authorized IP ranges and subnets by modifying settings in SmartConsole under Manage & Settings > Permissions & Administrators > Trusted Clients.
Although no active exploitation has been documented, Check Point advises security personnel to monitor for "Administrator failed to log in: Username too long" messages in the Audit and Admin login logs as indicators of CVE-2026-91843 attack attempts.
Check Point disclosed the flaw alongside two additional critical remote code execution vulnerabilities. One week prior, the company patched CVE-2026-85103, a heap overflow in VPN certificate ASN.1 decoding that impacts both firewalls and management systems. On the same day, it released a fix for CVE-2026-85102, which permits unauthenticated remote code execution on vulnerable firewalls.
According to Check Point, "All Security Management Server deployments are vulnerable, regardless of configuration. The vulnerability is not dependent on any specific management configuration. The management is vulnerable even when VPN in not in use or configured."
While these three vulnerabilities remain unexploited in the wild, Check Point has previously warned of active exploitation of other flaws. In June, a Qilin ransomware affiliate began exploiting CVE-2026-50751, an authentication bypass zero-day. A second authentication bypass zero-day, CVE-2026-16232, has been weaponized since at least July to gain administrator access to SmartConsole panels.
The Dutch National Cyber Security Centre (NCSC-NL) has urged organizations to prioritize patching CVE-2026-85102 and CVE-2026-85103, stating it "expects exploitation attempts to occur soon."