Check Point CVE-2026-91843 is a critical, remotely exploitable flaw in the login process of the company’s security-management and log servers. Check Point says an unauthenticated attacker could execute code with root privileges; administrators should apply the available updates or LivePatch and verify that the fix is active.
> Key takeaways > > – CVE-2026-91843 carries a 9.8 CVSS score and requires neither authentication nor user interaction. > – Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server releases. > – Check Point provides fixed software takes and a LivePatch; limiting the management interface to trusted clients is the fallback mitigation. > – Public notices reviewed for this article do not say the flaw is under active exploitation.
Check Point CVE-2026-91843: what is exposed
The flaw is a stack-based buffer overflow in the login path. That placement matters: the affected systems sit above security gateways and collect or administer sensitive network-security information, so a successful compromise would not be limited to a low-privilege application account.
Check Point’s notice says the weakness can let a remote, unauthenticated attacker run arbitrary code as root. Canada’s Cyber Centre independently lists the affected families as Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server. Latvia’s CERT.LV also published an alert describing the same impact and 9.8 severity score.
The practical answer is direct: Check Point CVE-2026-91843 is a management-plane risk, not merely a client-side bug. Organisations should prioritise internet-reachable or broadly accessible management servers, patch them, and then verify the installed fix rather than assuming automatic delivery succeeded.
Which releases need attention
CERT.LV lists R82.20, R82.10, R82, R81.20 and several end-of-support branches among affected releases, with exact exposure depending on installed Jumbo Hotfix takes. Its alert points administrators to fixed takes including R82.20 take 29, R82.10 take 28, R82 take 28 and R81.20 take 28.
Those take numbers should be checked against Check Point’s live support notice because vendors can revise remediation guidance. Customers using LivePatch should confirm the patch is installed rather than treating subscription status as proof; CERT.LV says the cplp list command should show the CVE-2026-91843 patch.
| Control | What it changes | Priority |
|---|---|---|
| Fixed take or Jumbo Hotfix | Removes the vulnerable login-path condition | Immediate |
| LivePatch verification | Confirms automatic protection actually landed | Immediate |
| Trusted Clients restriction | Limits who can reach the management web interface | Temporary fallback |
| Exposure review | Finds management servers reachable beyond intended admin networks | Same-day |
Why the management plane raises the stakes
Security-management servers are designed to control gateways, policy and logs. Root-level execution on that tier can therefore give an intruder a stronger position than compromise of an ordinary workstation, even though the public advisories do not document active exploitation.
That distinction should shape triage. Teams should first identify affected versions, check reachability, preserve logs and patch. If an update cannot be deployed immediately, Check Point’s mitigation is to restrict the web interface to trusted IP addresses or subnets through the Trusted Clients setting.
The disclosure follows a busy patch period across enterprise platforms. Lapaas Voice recently explained why Microsoft’s server-side cloud CVEs still require customer visibility and how CISA’s cyber-decoy guidance turns unexpected access into a signal. The common lesson is that a vendor fix only becomes operational protection when asset owners can prove where it landed.
FAQs
What is Check Point CVE-2026-91843?
It is a critical stack-based buffer overflow in the login process of Check Point security-management and log-server products. Successful remote exploitation can provide root-level code execution without authentication.
Is CVE-2026-91843 being actively exploited?
The Check Point and government notices reviewed for this report do not state that active exploitation has been observed. That is not a reason to delay patching because the flaw is remote, unauthenticated and rated 9.8.
What should administrators do first?
Inventory affected management and log servers, apply the relevant fixed take or LivePatch, verify installation, and restrict management access to trusted clients wherever patching cannot be completed immediately.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



