Check Point released an urgent security patch on September 16 for a critical vulnerability enabling unauthenticated attackers to run code as root on Security Management and Log Servers. The flaw, tracked as CVE-2026-91843 and rated 9.8 on the CVSS scale, exploits a stack overflow in the login process that occurs before authentication validation. The vulnerability requires only a single network request containing an excessively long username to trigger arbitrary code execution.
Internet scanning company Censys identified the attack vector as a login request carrying a very long username field. The stack overflow occurs in pre-authentication code paths, meaning attackers need no valid credentials or account access. Check Point’s Security Management Server controls firewall policy and administrator access across organizational networks. Successful exploitation grants complete system compromise through root-level code execution.
Check Point released the fix through its LivePatch automatic update channel and advised customers to apply advisory sk1000155 immediately. The company confirmed that systems with automatic updates enabled received protection automatically, though deployment occurred in stages rather than instantly across all customers. Customers without automatic updates must manually apply the patch urgently. Check Point stated that no evidence exists of active exploitation, though the vulnerability’s severity and wide attack surface warrant immediate patching across all deployments.
| CVE | Description | CVSS | Affected Products | Affected Versions | In the Wild | SK |
|---|---|---|---|---|---|---|
| CVE-2026-16232 | Authentication bypass with SmartConsole login using application token – Management | 9.3 | Security Management, Multi-Domain Management | R81.10, R81.20, R82, R82.10 (older versions impacted as well) | Yes, for a handful of customers with specific configurations. | sk185169 |
| CVE-2026-62144 | Management authentication bypass and privilege escalation | 9.3 | Security Management, Multi-Domain Management | R81.10, R81.20, R82, R82.10 (older versions impacted as well) | No | sk185152 |
| CVE-2026-62145 | Local privilege escalation in GaiaOS WebUI – Gateway | 7.5 | Firewall, Multi-Domain Management, Multi-Domain Log Server | R81.10, R81.20, R82, R82.10 (older versions impacted as well) | No | sk185153 |
The cybersecurity vendor has shared the below indicators of compromise (IoCs) associated with the activity:
- 151.241.99[.]207
- 151.241.99[.]233
- 158.62.198[.]182
- 192.142.10[.]99
- 139.28.37[.]250
- 194.213.18[.]137
Multiple product variants require patches. The Multi-Domain Security Management Server and Multi-Domain Log Server both require updates. Check Point’s hosted Smart-1 Cloud service required no fixes because patches were already deployed. However, R82.20 branch versions face a unique problem. Every build is affected and no Jumbo Hotfix currently protects this release. All older branches including R81 through R80 reached end-of-support status and receive no fixes, requiring complete version upgrades to remediate the flaw.
This marks the fifth critical unauthenticated management server flaw since July. Preceding vulnerabilities included CVE-2026-16232 (SmartConsole authentication bypass that saw exploitation), CVE-2026-62144 (second management bypass), CVE-2026-18574 (authentication bypass enabling command execution), and CVE-2026-85103 (heap overflow in VPN certificate decoding). The pattern reflects escalating security challenges in Check Point’s management infrastructure.
Internet scanning revealed approximately 3,836 hosts worldwide presenting the default identity Check Point assigns to management and log servers. However, Censys emphasized this figure reflects total role presence rather than confirmed vulnerable systems. Actual exposure depends on version checks, network accessibility and whether patches were deployed.
However, Check Point’s CVE record lists affected branches by Jumbo Hotfix Take. Administrators should verify their specific builds against advisory sk1000155. Until patches deploy, Check Point recommends restricting management trusted clients to known, specific internal IP addresses. Organizations should avoid exposing management interfaces directly to the internet. VPN-protected access further reduces attack surface.
