Check Point Software has shipped LivePatch updates to fix a critical vulnerability in its Security Management Server and Log Server products that could let an attacker with no credentials execute code as root over the network.

The flaw, tracked as CVE-2026-91843, is a stack-based buffer overflow in the login process used by Security Management Server instances, which control firewall policy and administrator access for Check Point Security Gateways. The same vulnerable code path affects the Log Server, which collects and stores logs from Check Point firewalls. Check Point says exploitation requires no user interaction and no prior privileges, and rates the attack complexity as low.

Detection and mitigation

Check Point has not confirmed in-the-wild exploitation of CVE-2026-91843, but it has published indicators of compromise for defenders. Security teams can look for “Administrator failed to log in: Username too long” entries in the Audit and Admin login logs as a sign of attempted exploitation.

For customers who cannot immediately apply LivePatch, Check Point recommends hardening exposed management systems and restricting access to trusted IP addresses or subnets. This can be done in SmartConsole under Manage & Settings, Permissions & Administrators, Trusted Clients. The company is urging customers without automatic updates enabled to patch immediately.

Part of a busy patch cycle for Check Point

This disclosure follows two other critical fixes issued by Check Point the prior week. CVE-2026-85103, a heap overflow in the VPN certificate ASN.1 decoding flow, affects both firewalls and management systems and, according to Check Point, impacts all Security Management Server deployments regardless of configuration, even when VPN is not in use. The same week, Check Point patched CVE-2026-85102, an unauthenticated bypass that allows remote code execution on vulnerable firewalls. The Dutch National Cyber Security Centre has urged organizations to prioritize patching both of those flaws, saying it expects exploitation attempts soon.

Check Point products have been a recurring target in 2026. A Qilin ransomware affiliate has exploited an authentication bypass zero-day (CVE-2026-50751) since June, while a separate zero-day (CVE-2026-16232) has been used since at least July to gain administrator access to SmartConsole panels.

Separately this week, Tanium patched several high- and medium-severity SQL injection and access control flaws across its Asset and Threat Response products, and Kaspersky disclosed that its Security 10 for Linux Mail Server is affected by a previously known Redis vulnerability from 2023 that could allow code execution when processing certain file formats.