Cybersecurity & Protection

Root Vulnerability Threatens Check Point Security Management and Log Servers

Sep 18, 2026 2 min read
All articles

A critical security vulnerability threatens Check Point's Security Management and Log Servers, including the Multi-Domain variants. In the worst case, attackers can fully compromise the affected systems. Check Point says it currently has no indication that the flaw is already being actively exploited.

The vulnerability, tracked as CVE-2026-91843, sits in the login process of the security solution that's actually meant to protect computers. According to the vendor's advisory, attacks are possible remotely and without prior authentication. Specially crafted login requests with extremely long usernames can trigger memory errors, which attackers can then use to execute malicious code with root privileges. With those privileges, an attacker can effectively disable any security setting or copy administrator credentials. A sign of a system that has already been successfully attacked is the entry "Administrator failed to log in: Username too long" in the SmartConsole log.

Several versions affected, some without support

According to Check Point, affected versions include R82.20, R82.10 with Jumbo Hotfix Take 44 or lower, R82 with Jumbo Hotfix Take 126 or lower, and R81.20 with Jumbo Hotfix Take 166 or lower. Support has already ended for R81.10 with Jumbo Hotfix Take 190 or lower, as well as for R80, R80.10, R80.20, R80.30, R80.40, and R81, meaning these versions no longer receive security patches. Admins running such installations need to upgrade to a version that's still supported.

Automatic updates already close the gap

The Smart-1 Cloud Environment is already considered secured. Anyone with automatic updates enabled should already have the fixed versions installed, for example R82.20 with bundle update Take 29, R82.10 with Take 28, R82 with Take 28, or R81.20 with Take 28. Anyone not updating automatically should install the matching patches manually right away and check their logs for signs of a possible prior compromise.