Remote Code Execution Vulnerability in Check Point Management Products
A critical remote code execution vulnerability (CVE-2026-91843) affects multiple Check Point security management servers, allowing unauthenticated attackers to execute arbitrary code.
CVE search metadata
CVE search record: CVE-2026-91843. Severity: critical. CVSS: 9.8. KEV: no. Product: Log Server (< R81.20 take 28, < R82 take 28, < R82.10 take 28, < R82.20 take 29), Multi-Domain Log Server (< R81.20 take 28, < R82 take 28, < R82.10 take 28, < R82.20 take 29), Multi-Domain Security Management Server (< R81.20 take 28, < R82 take 28, < R82.10 take 28, < R82.20 take 29), Security Management Server (< R81.20 take 28, < R82 take 28, < R82.10 take 28, < R82.20 take 29), Security Management Server, Log Server. Brief: Remote Code Execution Vulnerability in Check Point Management Products. Brief link: https://feed.craftedsignal.io/briefs/2026-09-checkpoint-rce/
What's new
- 1. new product Sep 18, 04:24 via the-hacker-news
On September 16, 2026, Check Point released security advisory sk1000155 addressing a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-91843. The vulnerability affects various Security Management and Log Server deployments, including Multi-Domain environments. Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the affected appliance. Defenders should audit logs for specific indicators of failed authentication attempts associated with username length anomalies.
Impact
Successful exploitation of CVE-2026-91843 results in total system compromise, enabling attackers to gain control over security management infrastructure, access sensitive logs, and potentially pivot into the protected network segments managed by the affected Check Point gateways. Organizations using Security Management Servers or Log Servers are at risk of complete administrative takeover.
Recommendation
- Patch all affected Check Point Security Management and Log Server instances by upgrading to the minimum version requirements specified in the vendor advisory (e.g., R81.20 take 28, R82 take 28, R82.10 take 28, or R82.20 take 29).
- Perform a retrospective audit of SmartConsole Audit and Admin login logs to identify the string "Administrator failed to log in: Username too long", which may indicate reconnaissance or exploitation attempts.
- Ensure all administrative management interfaces are restricted to trusted, segmented management networks and not exposed to the public internet.
Immediate actions
Audit security management logs for username length error patterns
Mitigations
Upgrade affected Check Point servers to minimum take versions
CVE-2026-91843