Critical Check Point Vulnerabilities Demand Immediate Attention from IT Security Professionals
Check Point Software has issued urgent security updates to address a critical stack-based buffer overflow vulnerability, **CVE-2026-91843**, affecting its Security Management Server and Log Server instances. This flaw could allow unprivileged attackers to execute code with root privileges remotely, underscoring the immediate need for patching across all deployments.
IT security professionals are urged to prioritize the immediate deployment of security updates from **Check Point Software** following the disclosure of a critical vulnerability, **CVE-2026-91843**. This flaw poses a significant risk, potentially allowing unprivileged attackers to gain root remote code execution on affected management systems.
### Unpacking CVE-2026-91843: A Critical Stack-Based Buffer Overflow
The vulnerability, tracked as **CVE-2026-91843**, stems from a stack-based buffer overflow weakness within the login process of **Security Management Server** instances. These servers are crucial for managing **Security Gateways** (firewalls) and monitoring network security events. The flaw also impacts **Check Point's Log Server**, a dedicated server for collecting and storing firewall logs.
Successful exploitation of **CVE-2026-91843** is alarmingly straightforward, requiring low complexity and no user interaction, allowing threat actors without privileges to achieve root remote code execution.
### Mitigation and Detection
For organizations unable to deploy the latest **LivePatch** immediately, **Check Point** has provided temporary mitigation strategies. These include hardening vulnerable systems and restricting access to trusted IP addresses/subnets by modifying entries under `Manage & Settings > Permissions & Administrators > Trusted Clients` in the **SmartConsole** dashboard.
While **Check Point** has not yet reported active exploitation of **CVE-2026-91843**, security teams can identify potential attacks by monitoring for "Administrator failed to log in: Username too long" alerts within the Audit and Admin login logs.

*CVE-2026-91843 alert in SmartConsole (Check Point Software)*
### A String of Recent Critical Vulnerabilities
This latest disclosure follows a series of critical vulnerabilities patched by **Check Point** in recent weeks. Last week, the company addressed another critical remote code execution flaw, **CVE-2026-85103**. This heap overflow vulnerability, found in the VPN certificate ASN.1 decoding flow, affects both **Check Point** firewalls and management systems.
**Check Point** explicitly warned that "All Security Management Server deployments are vulnerable, regardless of configuration." This means the vulnerability persists even if VPN functionality is not in use or configured.
Simultaneously, a second critical flaw, **CVE-2026-85102**, was patched. This allows unauthenticated hackers to bypass authentication and execute code remotely on vulnerable firewalls.
### Actively Exploited Threats and Urgent Warnings
While **CVE-2026-91843**, **CVE-2026-85103**, and **CVE-2026-85102** are not yet confirmed as actively exploited, **Check Point** has previously flagged other critical flaws that have been actively abused in the wild. Notably, an authentication bypass zero-day, **CVE-2026-50751**, was exploited by a **Qilin ransomware** affiliate since June. Another authentication bypass zero-day, **CVE-2026-16232**, has been exploited since at least July to gain administrator privileges to **SmartConsole** admin panels.
The **Dutch National Cyber Security Centre (NCSC-NL)** recently issued a stark warning, urging organizations to prioritize patching **CVE-2026-85102** and **CVE-2026-85103**, anticipating imminent exploitation attempts.
The repeated emergence of critical vulnerabilities, some already under active exploitation, underscores the vital importance of maintaining diligent patching schedules and robust security hygiene for all **Check Point** deployments.