Anyone able to reach a Check Point customer’s Security Management Server can take it over, the vendor warned on September 16. The vulnerability is CVE-2026-91843, rated 9.8, and it sits in the login process that handles requests before a user is authenticated.
Censys traced the trigger to one oversized field. A login request carrying an extremely long username overflows a stack buffer, and the overflow ends up inside code running as root. Nothing else is needed: no account, no credentials, no token, only network access to the Security Management or Log Server.
Exposure narrows for customers who use the Trusted Clients setting, the list that governs which hosts may connect through SmartConsole. Sites whose management interface is reachable from a wider network carry more risk.
Fixes arrived through the LivePatch channel, so organisations with automatic updates enabled are already covered. Everyone else needs to apply the update in advisory sk1000155. Affected builds run from R81.10 through R82.20, plus a long tail of end-of-support releases.
The vendor says it has no indication of exploitation. CISA’s assessment attached to the CVE record rates exploitation as none. Exploit code was still absent from public view on September 16, Censys reported.
For defenders the work is short. Confirm the installed take number, apply the LivePatch, and check whether the management server answers on any interface outside its trusted client list. A pre-auth root hole in firewall management is the kind of bug that stops being theoretical the moment someone publishes a working exploit.
