The Maivia Gazette

Verified AI news, every morning

Security

Check Point patches a login buffer overflow that gives unauthenticated attackers root on management servers

CVE-2026-91843 affects Security Management Server and Log Server, and admins can spot attempts by watching for 'Username too long' login failures.

Editorial illustration about Check Point patches a login buffer overflow that gives unauthenticated attackers root on management servers.
AI-generated illustration, not event photography. The motion is AI-generated from the still.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.

Check Point Software has released security updates for a critical vulnerability that lets attackers execute code with root privileges on the systems that manage its firewalls. Tracked as CVE-2026-91843, the flaw is a stack-based buffer overflow in the login process of Security Management Server instances, which administer Security Gateways and monitor network security events. It also affects the company's Log Server, which collects and stores logs from Check Point firewalls. Exploitation requires no privileges and no user interaction, and the attack is low in complexity. The fix ships as a LivePatch. For customers who cannot deploy it immediately, Check Point recommends hardening the systems and restricting access to trusted IP addresses or subnets through the Trusted Clients settings in the SmartConsole dashboard. The company has not flagged the flaw as actively exploited, but it says security teams can identify attempts by looking for "Administrator failed to log in: Username too long" alerts in the audit and admin login logs. The disclosure comes a week after Check Point patched two other critical flaws in its VPN gateways that the Dutch national cyber security centre warned were likely to be exploited soon. Management servers are high-value targets because compromising one gives control over every firewall it administers.

Sources

  1. BleepingComputerNew Check Point flaw lets hackers execute code with root privilegesPublished · fetched
  2. The Hacker NewsCritical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as RootPublished · fetched

Also in this edition