Vulnerabilities & Exploits

Check Point Login Overflow Reaches Root on Management Servers

Check Point patched CVE-2026-91843, a critical stack overflow in the pre-auth Trusted Clients login path of its Security Management Server and Log Server that can let an unauthenticated attacker run code as root. Check Point says it has no indication of exploitation, and it has released LivePatch fixes for affected branches, including R82.20.

The bug sits before authentication: a login request with an overlong username can overflow memory in the management service’s login process. Because that process runs on the box that controls firewall policy and administrator access, root there means the attacker can take over the control plane, not just crash a service.

For shops that expose management interfaces to Trusted Clients hosts, the blast radius is the management plane itself, and that is what persists after the patch story is over: any host that can reach that front door inherits the risk until the exposure is closed off or updated. CISA lists no known exploitation so far, so this is a high-impact vulnerability, not an active-campaign report.

5 sources · Sep 18

CVE-2026-91843

NVD KEV

CVSS 9.8 CRITICAL: a stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with…

Timeline

Sources

Part of the PlainSec briefing for 2026-09-19

Every edition of this story: Check Point Login Overflow Reaches Root on Management Servers

More from today