Critical Check Point management flaw lets unauthenticated attackers gain root
Check Point patched a critical flaw in its management servers that lets an unauthenticated attacker run code as root. Tracked as CVE-2026-91843 and scored 9.8, it is a stack overflow in the login process, which handles requests before a user authenticates, and it can be triggered by a login request carrying an overly long username. It affects Quantum management, Log, and Multi-Domain servers, through the Trusted Clients path. Customers with automatic updates are already protected, and others should apply the vendor's live patch. Check Point reports no exploitation yet, but this is the third serious management-server flaw it has disclosed in weeks, and compromising it means control over the whole firewall estate.
- Check
- Apply Check Point's live patch for the management-server flaw now if automatic updates are not enabled, and restrict which clients can reach the management, Log, and Multi-Domain servers.
- Affected
- Organizations running affected Check Point Quantum management, Log, or Multi-Domain servers (CVE-2026-91843); an unauthenticated attacker can trigger a login overflow with a long username to run code as root.
- Fix
- Patch or confirm automatic updates applied, tightly restrict access to management-plane servers, monitor for anomalous pre-authentication login traffic, and treat the management plane as the highest-value target since it controls every firewall.