Back Heise.De Root security flaw endangers Check Point Security Management and Log Servers
Attackers can attack Check Point Security Management and Log Servers – including the Multi-Domain variants – and in the worst case, completely compromise systems. So far, there are no indications from Check Point that attackers are already exploiting the vulnerability.
Check Point’s IT security solution is actually supposed to protect computers from attacks. However, the “ critical ” security vulnerability (CVE-2026-91843) now opens the doors for attackers. In a warning message, the developers write that attacks are possible remotely and without authentication.
According to the brief description, the vulnerability lies in the login process. Apparently, attackers can trigger memory errors through prepared login requests with extremely long usernames. Subsequently, they should be able to execute malicious code with root privileges.
Equipped with such rights, attackers usually have a free pass and can do whatever they want. For example, they can disable security settings or copy administrator credentials.
An indication of already successfully attacked systems is the entry “ Administrator failed to log in: Username too long ” in the SmartConsole log.
The developers state that the following versions are threatened. Support has expired for some versions (EoS), so they no longer receive security patches. Here, administrators must upgrade to supported versions.
R82.10 Jumbo Hotfix Take 44 or lower
R82 Jumbo Hotfix Take 126 or lower
R81.20 Jumbo Hotfix Take 166 or lower
R81.10 Jumbo Hotfix Take 190 or lower (EoS)
R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS)
Smart-1 Cloud Environment is reportedly already secured. If automatic updates are enabled, the following repaired versions are also already installed:
R82.20 BUNDLE_URGENT_SECURITY_UPDATE_R82_10_AUTOUPDATE take 29
R82.10 BUNDLE_URGENT_SECURITY_UPDATE_R82_10_AUTOUPDATE take 28
R82 BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE take 28
R81.20 BUNDLE_URGENT_SECURITY_UPDATE_R81_20_AUTOUPDATE take 28
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
