Overview
- Check Point posted advisory sk1000155 around Sept. 16–17 and released a LivePatch to fix CVE-2026-91843, a vulnerability rated 9.8 that the company says it has pushed to systems with automatic updates.
- Researchers at Censys and Check Point say the defect is a stack‑based buffer overflow triggered by a login request with an overly long username, which can let an unauthenticated attacker execute arbitrary code as root.
- The flaw affects multiple branches, including R82.20 and several older R80/R81 releases, and reaches standalone deployments, Log Servers and Multi‑Domain servers when the Trusted Clients setting permits SmartConsole connections.
- There is no public evidence of exploitation so far and CISA marked exploitation as "none," but administrators must confirm the LivePatch is installed because staged rollouts can delay automatic delivery and hosts should restrict Trusted Clients and avoid exposing management to the internet.
- This is the latest of five recent critical management‑server flaws since July, Censys reports about 3,836 hosts advertising the management/log role on the internet as an upper bound of exposure, and the pattern raises pressure on teams to patch quickly and tighten access controls.