Check Point released fixes for CVE-2026-91843, a critical (CVSS 9.8) stack-based buffer overflow in the login process of its Security Management and Log Server products. A remote, unauthenticated attacker can reportedly submit an excessively long username to execute arbitrary code with root privileges before authentication. Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server across R81.20, R82, R82.10, R82.20, and certain older releases; Smart-1 Cloud is not affected.
Administrators should urgently deploy Check Point’s LivePatch or applicable offline updates, verify remediation on every management and logging server, and review failed-login records for oversized-username attempts. Organizations should also restrict SmartConsole Trusted Clients until patching is validated. Check Point has not reported active exploitation or disclosed a public exploit chain; releases earlier than R81.20 are end of support and will not receive patches, requiring an upgrade or replacement strategy.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-933 covering CVE-2026-91843 in Check Point Security Management, Multi-Domain Security Management, Log Server, and Multi-Domain Log Server products. It advised administrators to review Check Point guidance and apply applicable updates.
Check Point issued security updates, including LivePatch and offline urgent updates, for CVE-2026-91843, a CVSS 9.8 stack-based buffer overflow in Security Management and Log Server products. The flaw can be triggered before authentication using an excessively long username and may permit unauthenticated remote code execution with root privileges; unsupported releases earlier than R81.20 will not receive patches.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourceacn.gov.it
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.