Skip to content
Critical Check Point Vulnerability Allows Root Code Execution via Long Username

Critical Check Point Vulnerability Allows Root Code Execution via Long Username

First seen 18 Sep 2026, 08:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 09:55 UTC
  • CVE-2026-91843 allows root code execution via a long username.
  • Check Point released a patch on September 16, 2026, urging immediate application.
  • This vulnerability is the fifth critical issue in Check Point's management servers since July.

A critical vulnerability in Check Point's Security Management and Log Servers, tracked as CVE-2026-91843, allows unauthenticated attackers to run code as root by sending a network request with an excessively long username. Rated 9.8 on the CVSS scale, this stack overflow occurs in the login process before authentication. Check Point released a patch on September 16, 2026, through its LivePatch channel, advising immediate application for customers without automatic updates. The vulnerability affects multiple branches, including R82.10 and R82.20, with the latter lacking a protective Jumbo Hotfix. No evidence of exploitation has been reported, but the potential impact is severe. The flaw marks the fifth critical unauthenticated management server issue since July 2026, highlighting escalating security challenges for Check Point. Censys identified approximately 3,836 hosts worldwide that may be vulnerable, although actual exposure depends on version checks and patch deployment.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-22
CVE-2026-16232 published
Check Point disclosed a SmartConsole authentication bypass vulnerability, later exploited.
Techjuice.Pk
2026-07-22
CVE-2026-62144 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-03
CVE-2026-18574 published
Check Point announced another critical authentication bypass vulnerability enabling command execution.
Techjuice.Pk
2026-09-09
CVE-2026-85103 published
Check Point disclosed a heap overflow vulnerability in VPN certificate decoding.
Techjuice.Pk
2026-09-16
Patch released for CVE-2026-91843
Check Point released an urgent patch for the critical vulnerability allowing root code execution.
The Hacker News
2026-09-17
CISA reports no exploitation
CISA confirmed no indications of exploitation for CVE-2026-91843 in its assessment.
The Hacker News

More articles in this cluster (4)

Following this threat?

Track CVE-2026-16232 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed