important · Edge / RCE
A crafted Check Point management login can execute code as root before authentication.
Affects
Check Point Security Management, Multi-Domain Security Management, Log, and Multi-Domain Log Servers controlling and recording security infrastructure.
The reported overlong-username trigger reaches a stack overflow in the login process; Trusted Clients restrictions can narrow which source hosts reach it.
Detail and 4 sources
Check Point provides fixed releases and LivePatch, but the fix was not read for a Priority Finding.
Sources
ResearchKritiska Check Point ievainojamība (CVE-2026-91843) | CERT.LVResearchCheck Pointのセキュリティ管理サーバに認証前のスタックオーバーフロー脆弱性CVE-2026-91843(CVSS 9.8)— 攻撃者はroot権限で遠隔コード実行、同社はLivePatchで修正 | NEXSIGHT CYBER WIREResearchhttps://support.checkpoint.com/results/sk/sk1000155SecondaryCheck Point security advisory (AV26-933)