Threat Landscape

Check Point CVE-2026-91843 is CVSS 9.8. Unauth root on the management plane.

Stack overflow in the login path. Security Management, Log Server, Multi-Domain, standalone. LivePatch sk1000155. No ITW yet. Censys ~3,836 mgmt hosts (role presence, not vuln count). Count Undisclosed.

Sep 18, 2026 · 4 min read

The box that pushes firewall policy should not accept unauthenticated root. This week it could.

On September 18 SecurityWeek and BleepingComputer covered CVE-2026-91843 — a critical stack-based buffer overflow in the Check Point Security Management / Log Server login process. Check Point’s own CNA score on NVD: CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Description: a stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges. NVD lists CWE-121. Primary advisory: sk1000155.

The Hacker News (updated Sep 18 with Check Point responses) adds the operational frame: the vulnerable path runs through the Trusted Clients setting (which hosts may connect to management via SmartConsole). Censys says the overflow is triggered by a login request with a very long username. Hunt signal Check Point shared: Audit / Admin login logs showing “Administrator failed to log in: Username too long.” Affected roles per Check Point / THN: Security Management, Log Servers, Multi-Domain, and standalone (management+gateway on one box). Smart-1 Cloud is not affected — NHS England Digital citing sk1000155 says the hosted fix is already in place. R82.20 is vulnerable (Abramovich to THN / Censys); Jumbo Hotfix takes listed on NVD for R82.10 / R82 / R81.20 / R81.10 (EOS) and older EOS branches. Fix for EOS builds is via Check Point support ticket, not a public Jumbo alone.

Exploitation status — say it carefully: Check Point’s CheckMates notice (Sep 16) and Abramovich to THN: no indication of in-the-wild exploitation. CISA’s assessment attached to the CVE recorded exploitation as “none” (THN, Sep 17 check). Not on CISA KEV as of THN’s Sep 17 check. Censys: no public PoC as of Sep 16. That is not a free pass — Check Point management has already seen critical unauth paths this summer (CVE-2026-16232 SmartConsole bypass was exploited and KEV’d; THN counts CVE-2026-91843 as the fifth critical management-reachable flaw since July 22). Dutch NCSC separately urged priority patching on related VPN cert RCEs last week expecting exploitation attempts soon.

Exposure estimate: Censys observes 3,836 hosts worldwide presenting Check Point’s default management / log-server identity. Censys itself: “total role presence, not a confirmed-vulnerable count.” 3,836 is not a vuln census. Victim / compromise count: Undisclosed.

Mitigate now, sourced: apply the LivePatch in sk1000155 to every Security Management and Log Server; if automatic updates (sk175504) are on, still verify with cplp list rather than assume. Limit Trusted Clients to known hosts — not “any IP.” Do not expose management directly to the internet. Temporary hardening if LivePatch is delayed: Trusted Clients IP allowlists in SmartConsole (Manage & Settings → Permissions & Administrators → Trusted Clients), per BleepingComputer / Check Point hardening guidance.

POV: Unauth root on the management plane is the class of bug that turns into weekend IR the week after someone publishes a PoC. Check Point already lived that movie with CVE-2026-16232. Patch sk1000155 today. Confirm LivePatch armed. Shrink Trusted Clients. Count of successful breaches stays Undisclosed. Sources: Check Point sk1000155 / NVD CVE-2026-91843, SecurityWeek Sep 18, BleepingComputer Sep 18, The Hacker News Sep 17–18 update.

Underwrite sheet — sourced only: CVE-2026-91843; CVSS 9.8 (Check Point CNA / NVD); stack overflow unauth login → root RCE; Security Management + Log Server + Multi-Domain + standalone; Trusted Clients path (THN / Check Point); IoC “Username too long”; LivePatch sk1000155; Smart-1 Cloud not affected; R82.20 vulnerable; no ITW / CISA exploitation “none” / not on KEV (as of THN Sep 17); Censys ~3,836 mgmt-role hosts (not vuln count); fifth critical mgmt flaw since Jul 22 (THN); victim count Undisclosed.

Sources