Skip to content
Threat Feed
high advisory updated

Remote Code Execution Vulnerability in Check Point Management Products

A critical remote code execution vulnerability (CVE-2026-91843) affects multiple Check Point security management servers, allowing unauthenticated attackers to execute arbitrary code.

CVE search metadata

CVE search record: CVE-2026-91843. Severity: critical. CVSS: 9.8. KEV: no. Product: Log Server (< R81.20 take 28, < R82 take 28, < R82.10 take 28, < R82.20 take 29), Multi-Domain Log Server (< R81.20 take 28, < R82 take 28, < R82.10 take 28, < R82.20 take 29), Multi-Domain Security Management Server (< R81.20 take 28, < R82 take 28, < R82.10 take 28, < R82.20 take 29), Security Management Server (< R81.20 take 28, < R82 take 28, < R82.10 take 28, < R82.20 take 29), Security Management Server, Log Server. Brief: Remote Code Execution Vulnerability in Check Point Management Products. Brief link: https://feed.craftedsignal.io/briefs/2026-09-checkpoint-rce/

What's new

On September 16, 2026, Check Point released security advisory sk1000155 addressing a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-91843. The vulnerability affects various Security Management and Log Server deployments, including Multi-Domain environments. Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the affected appliance. Defenders should audit logs for specific indicators of failed authentication attempts associated with username length anomalies.

Impact

Successful exploitation of CVE-2026-91843 results in total system compromise, enabling attackers to gain control over security management infrastructure, access sensitive logs, and potentially pivot into the protected network segments managed by the affected Check Point gateways. Organizations using Security Management Servers or Log Servers are at risk of complete administrative takeover.

Recommendation

  1. Patch all affected Check Point Security Management and Log Server instances by upgrading to the minimum version requirements specified in the vendor advisory (e.g., R81.20 take 28, R82 take 28, R82.10 take 28, or R82.20 take 29).
  2. Perform a retrospective audit of SmartConsole Audit and Admin login logs to identify the string "Administrator failed to log in: Username too long", which may indicate reconnaissance or exploitation attempts.
  3. Ensure all administrative management interfaces are restricted to trusted, segmented management networks and not exposed to the public internet.

Immediate actions

Audit security management logs for username length error patterns

SOC 24h

Mitigations

Upgrade affected Check Point servers to minimum take versions

immediate IT Operations

CVE-2026-91843