"At this time, there is no indication that this vulnerability has been exploited in the wild," Check Point wrote on its CheckMates community on September 16, 2026.
What the flaw is and how it can be triggered (CVE-2026-91843)
Check Point has assigned CVE-2026-91843 to a critical stack overflow in the login process of its Security Management and Log Servers. The company rated the flaw 9.8 out of 10 on the CVSS scale. According to Check Point and Censys, the overflow is triggered by a login request that carries a very long username, and the vulnerable code runs before a user is authenticated.
Check Point told The Hacker News that the vulnerable path runs only through the Trusted Clients setting — the control that decides which hosts may connect to the management server through SmartConsole. Aviv Abramovich, vice president of product management for network security at Check Point, confirmed to The Hacker News that the vulnerable path is "only through trusted clients."
Affected versions, deployments, and exceptions
Check Point's CVE record lists multiple branches and Jumbo Hotfix Take levels as affected. A server on a listed branch at the listed Take or an older one is affected. The record lists the following branches as affected:
- R82.10 with Jumbo Hotfix Take 44 or below
- R82 with Jumbo Hotfix Take 126 or below
- R81.20 with Jumbo Hotfix Take 166 or below
- R81.10 with Jumbo Hotfix Take 190 or below, and R81, R80.40, R80.30, R80.20, R80.10 and R80 — all of which are end of support
Although R82.20 was not listed in the CVE record, Abramovich told The Hacker News that R82.20 is also vulnerable. Censys said every R82.20 build is affected and that no Jumbo Hotfix yet protects that branch. Check Point also confirmed that standalone deployments (management and gateway on one system), Log Servers and Multi‑Domain servers are vulnerable. NHS England Digital cited advisory sk1000155 and said the hosted Smart‑1 Cloud service is not affected because the fix is already in place there.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleImmediate actions Check Point tells administrators to take
- Apply the LivePatch fix described in advisory sk1000155 to every Security Management Server and Log Server.
- If automatic updates are enabled, do not assume protection — confirm the fix has been installed. The cplp list command shows which LivePatches are installed and their status.
- Whether or not the fix is installed, verify the management Trusted Clients access is limited to known, trusted hosts and is not set to any IP address; do not expose management access directly to the internet.
Check Point explains that "automatic updates" refers to the setting described in sk175504 — the checkbox in SmartConsole under Global Properties and Data Access Control labeled "Automatically download and install Software Blade Contracts, security updates, and other important data (highly recommended)," followed by the installation of the Access Control policy. LivePatch is the channel Check Point uses to push urgent fixes to systems where that option is turned on.
Check Point warned customers to take immediate action because of the flaw's severity and potential impact. The company said customers with automatic updates enabled are already protected but urged everyone else to apply the LivePatch. It also noted that LivePatch delivery may be staged: previous urgent fixes were rolled out in phases and some customers reported the automatic package had not reached their systems on the day of announcement.
Exposure signals and recent management-server flaws
Censys reported observing 3,836 hosts worldwide that present the default identity Check Point assigns to its management and log servers. Censys cautioned this is a "total role presence, not a confirmed‑vulnerable count," because build and hotfix levels are not visible in scan data. As of September 16, Censys said no public proof‑of‑concept exploit existed.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recorded exploitation as "none" in its assessment attached to the CVE record on September 17. The flaw was not in CISA's Known Exploited Vulnerabilities catalog as of the catalog's September 16 release; by contrast, CISA added CVE‑2026‑16232 to that catalog the day it was exploited in July.
By The Hacker News' count of Check Point CVE records, CVE‑2026‑91843 is the fifth critical flaw since July 22 that an attacker could reach on the Security Management Server without logging in. Prior entries included CVE‑2026‑16232 (a SmartConsole authentication bypass exploited in July), CVE‑2026‑62144 (disclosed the same day but not reported as exploited), CVE‑2026‑18574 (an authentication bypass on August 3), and CVE‑2026‑85103 (a heap overflow in VPN certificate decoding on September 9).
What this means for security teams, cloud customers, and regulators
- Security teams and administrators: Confirm LivePatch installation with cplp list, immediately apply sk1000155 where missing, and restrict Trusted Clients to known host addresses rather than allowing any IP. Do not expose management interfaces directly to the internet.
- Cloud and managed‑service customers (for example, hosted Smart‑1 Cloud users): Verify provider statements — NHS England Digital cited that Smart‑1 Cloud had the fix already in place — and seek confirmation from vendors when fixes are rolled out.
- Regulators and incident responders (CISA and similar bodies): Track whether exploitation status changes; CISA's assessment attached to the CVE currently records "none," and the flaw was not in the Known Exploited Vulnerabilities catalog as of September 16.
Check Point said it has no indication of exploitation and that customers with automatic updates enabled are likely already protected, but also urged immediate, manual verification and patching. The company made a fix available for out‑of‑support versions through support tickets, Abramovich said. With at least five critical management‑path flaws disclosed since late July, administrators are left to verify that automated defenses have reached their systems and to double‑check access controls on management servers.




