CVE-2026-91843: Unauthenticated Stack Overflow in Check Point Security Management Servers
Overview
CVE-2026-91843 is a critical remote code execution flaw in Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server. CERT-In published the note as CIVN-2026-0465 on 18 September 2026 and rated it CRITICAL. The defect is a stack overflow that is reachable before authentication.
Mechanism and exploitation conditions
The overflow sits in the unauthenticated login process. A remote attacker sends a specially crafted request to the login handler; the malformed input overflows a stack buffer and lets the attacker divert execution. Because the vulnerable path is pre-authentication, no valid credentials and no prior network position beyond reachability to the management interface are required. Successful exploitation yields arbitrary code execution with root privileges on the targeted server.
Impact
A compromised management server is a high-value position. These systems hold security policies, gateway configuration and log data. Root access on a management or log server can let an attacker alter policy, disable enforcement, read or tamper with stored logs, and pivot toward managed gateways.
Affected products and versions
- Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server
- R82.20
- R82.10 Jumbo Hotfix Take 44 or prior
- R82 Jumbo Hotfix Take 126 or prior
- R81.20 Jumbo Hotfix Take 166 or prior
- R81.10 Jumbo Hotfix Take 190 or prior (end of support)
- R80, R80.10, R80.20, R80.30, R80.40, R81 (all end of support)
Remediation and mitigation
Apply the vendor fixes described in Check Point advisory sk1000155 and the CERT-In note. Where an affected build cannot be updated immediately, restrict management and log server interfaces to trusted administrative networks and monitor for unexpected login traffic. End-of-support releases should be upgraded to a supported train.
Sources
- CERT-In Vulnerability Note CIVN-2026-0465
- Check Point advisory sk1000155
Top comments (0)