Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-19 · updated: 2026-09-19 · tags: [incident, government] · confidence: high · severity: critical · affected_sectors: [government] · au_impact: true

Check Point has released security updates for a critical stack-based buffer overflow in the login process of Security Management Server, the component that manages Security Gateways and monitors network events, which also affects the dedicated Log Server. Tracked as CVE-2026-91843, the flaw lets an unprivileged, unauthenticated attacker gain root remote code execution in a low-complexity attack requiring no user interaction. Check Point states that all Security Management Server deployments are vulnerable regardless of configuration. For customers who cannot apply the LivePatch immediately, the vendor recommends hardening vulnerable systems and restricting access to trusted IP addresses and subnets via Manage & Settings > Permissions & Administrators > Trusted Clients in SmartConsole, and says administrators can hunt for exploitation by searching Audit and Admin login logs for "Administrator failed to log in: Username too long" alerts. Check Point has not marked the flaw as actively exploited; last week it patched CVE-2026-85103, a heap overflow in VPN certificate ASN.1 decoding.

Attribute Detail
Sector Government
Date 2026-09-19
Source BleepingComputer
Reliability Tier 2
CVEs CVE-2026-85103, CVE-2026-91843