Check Point Issues Critical CVE-2026-91843 Patch: How to Secure Management Servers

Check Point Software has released emergency patches to address a critical vulnerability in its security management and log servers that could allow unauthenticated attackers to gain root-level control over affected systems. The flaw, tracked as CVE-2026-91843, carries a CVSS v3.1 score of 9.8, reflecting its potential for remote code execution without requiring valid credentials.

The vulnerability stems from a stack-based buffer overflow within the login process. By sending a specially crafted request, an attacker can trigger the overflow to execute arbitrary code with the highest possible privileges. While the vulnerability is severe, Check Point stated on September 18, 2026, that there is currently no evidence of the flaw being exploited in the wild.

Abstract visualization of a software buffer overflow vulnerability.
involves a stack-based buffer overflow in the server login process.

Scope of Impact and Affected Versions

The flaw specifically targets the management plane of Check Point’s infrastructure rather than the firewall gateways themselves. Affected products include the Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server.

Security administrators should verify if they are running the following vulnerable versions:

  • R82.20: All initial deployments.
  • R82.10: Take 44 or lower.
  • R82: Take 126 or lower.
  • R81.20: Take 166 or lower.

Detection and Immediate Mitigation

Check Point is delivering the fix primarily through its LivePatch channel. Systems configured with automatic updates may have already received the protection without requiring a reboot. For manual verification and installation, administrators should refer to the official advisory sk1000155 available in the Check Point Support Center.

A minimalist security dashboard showing system logs and alerts.
Administrators can check login logs for specific error strings to detect potential breach attempts.

While the “Trusted Clients” configuration in Check Point Management can restrict which IP addresses are permitted to attempt a login, the underlying vulnerability remains present in the code of unpatched systems, making the LivePatch update the primary line of defense.

More From Category

More Stories Today