Check Point Vulnerability Lets Remote Hackers Gain Root Access Without Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Check Point has released an urgent security fix for CVE-2026-91843, a critical stack-based buffer overflow that could let an unauthenticated remote attacker execute arbitrary code with root privileges on vulnerable security management and logging systems.

The flaw carries a CVSS 3.1 score of 9.8, reflecting a network-accessible attack requiring low complexity, no privileges, and no user interaction.

The vulnerability occurs during login, where an excessively long attacker-controlled username can trigger a stack overflow before authentication completes.

Successful exploitation could give an adversary the highest level of operating-system control, potentially exposing management data, security policies, administrator information, and collected logs while enabling further compromise of the protected environment.

Check Point Vulnerability Enables Root Access

Check Point has not publicly described the exploit chain or said it has observed attacks in the wild. Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server.

Vulnerable releases comprise R82.20; R82.10 with Jumbo Hotfix Take 44 or earlier; R82 with Take 126 or earlier; R81.20 with Take 166 or earlier; and end-of-support R81.10 with Take 190 or earlier. R80 through R80.40 and R81, which are also end-of-support, remain affected.

According to the advisory published by Check Point, Check Point says Smart-1 Cloud is not vulnerable because the correction has already been deployed in that environment.

Defenders should immediately examine SmartConsole Audit and Admin login records for the message “Administrator failed to log in: Username too long.”

This entry may indicate an attempt to deliver the oversized input associated with the flaw, although teams should investigate surrounding activity before treating it as proof of successful root-level compromise.

Preserve relevant source addresses, timestamps, administrator login events, configuration changes, and unusual management-server processes for incident-response analysis.

Check Point has delivered the correction through Check Point LivePatch. Customers with automatic security updates enabled under sk175504 should receive protection automatically, but administrators should verify deployment rather than assume coverage.

Offline packages are available as urgent security update Take 29 for R82.20 and Take 28 for R82.10, R82, and R81.20. The LivePatch must be installed across every affected Security Management, Multi-Domain Security Management, and Log Server.

Administrators can validate protection by entering Expert mode and running cplp list on each management or log server. A protected system should show the fwm:fwm patch in “armed” status with “livepatch” mode and CVE-2026-91843 in the comment field.

Until remediation is confirmed, organizations should restrict SmartConsole Trusted Clients to approved IP addresses or subnets through Manage & Settings, Permissions & Administrators, and Trusted Clients.

Check Point specifically warns against selecting “Any” as the client type. Because compromise would yield root access without credentials, exposed management interfaces and unsupported releases warrant immediate action, with migration to a supported branch treated as a priority rather than a substitute for applying the available fix.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Check Point Vulnerability Lets Remote Hackers Gain Root Access Without Authentication appeared first on Cyber Security News.