Check Point has issued a critical security update to address CVE-2026-91843, a severe stack-based buffer overflow vulnerability. This flaw enables remote attackers to execute arbitrary code with root privileges without requiring authentication, affecting security management and logging systems.
Details of the Vulnerability
The vulnerability is marked with a CVSS 3.1 score of 9.8, highlighting its potential impact. It involves network-accessible attacks that are low in complexity and do not need any user interaction or prior access privileges. The issue arises during the login process when an attacker can exploit a stack overflow by using an excessively long username before authentication is completed.
If successfully exploited, attackers could gain full control over the operating system. This could lead to exposure of sensitive data, including security policies, management data, administrator information, and collected logs, potentially compromising the entire protected environment.
Affected Products and Recommendations
Check Point has not disclosed specific details about the exploit chain or observed any in-the-wild attacks. The affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server. The affected versions are R82.20, R82.10 with Jumbo Hotfix Take 44 or earlier, R82 with Take 126 or earlier, and R81.20 with Take 166 or earlier, along with several end-of-support versions.
Check Point has confirmed that Smart-1 Cloud is not affected, as updates have already been applied. Administrators are advised to check SmartConsole Audit and Admin login records for any unusual activity, such as messages indicating attempts to exploit the flaw with excessively long usernames. It is crucial to preserve logs and details like source addresses and timestamps for further analysis.
Steps for Mitigation
Check Point has deployed the fix via Check Point LivePatch. Customers with automatic updates enabled should receive the patch automatically, but manual verification is recommended to ensure full protection. Offline updates are available for urgent application, specifically Take 29 for R82.20 and Take 28 for R82.10, R82, and R81.20. Administrators should ensure the patch is applied to all affected servers.
Organizations should enforce IP restrictions on SmartConsole Trusted Clients to prevent unauthorized access. Avoid setting the client type to “Any” to mitigate the risk of root access without credentials. Immediate action is recommended for unsupported releases, either through migration to a supported version or by applying the available fix.
Prompt action and thorough investigation of any suspicious activity are crucial for maintaining security and preventing potential breaches. Comprehensive incident response and timely updates will help bolster defenses against this critical vulnerability.
