Check Point patches critical login flaw that hands attackers root on firewall management servers

CVE-2026-91843 is the third critical bug in a fortnight for Check Point, and two earlier authentication bypasses are already being exploited in the wild.

ThreatVectr Newsdesk· Editor: Lee Brown· 4 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit corporate server room, rows of dark rack-mounted network firewall appliances with glowing amber
Share

Key points

  • Check Point has patched CVE-2026-91843, a critical flaw scored 9.8 out of 10 that lets an attacker with no password take full control of the server running a company's firewalls.
  • The bug affects Security Management Server and Log Server systems, the machines that run and record activity for Check Point firewalls.
  • Two earlier Check Point authentication bypasses, CVE-2026-50751 and CVE-2026-16232, are already being attacked, with US federal agencies ordered to patch them by 11 June and 25 July 2026 respectively.
  • One of those active attacks is being run by an affiliate of the Qilin ransomware gang, which breaks into companies, steals files and encrypts the originals.
  • This is the ninth Check Point story we've published since 30 June, and the pattern is not getting better.

Check Point, one of the biggest sellers of corporate firewalls, has released an emergency fix for a flaw that lets a stranger on the internet take over the server controlling a company's entire firewall estate.

The bug is tracked as CVE-2026-91843 and carries a severity score of 9.8 out of 10. It sits in the login screen of Check Point's Security Management Server, the central console administrators use to run their firewalls. A firewall is the piece of network equipment that decides what traffic is allowed in and out of a company's network.

The flaw is a stack-based buffer overflow, a very old class of programming bug where sending an over-long input tricks the software into running the attacker's own commands. Those commands run as root, the highest level of access a system can grant. No password required, no click needed from any user. Check Point's Log Server, which stores records of firewall activity, is affected as well.

Is this being exploited in the wild?

Not yet, according to Check Point. The company has published the patch alongside temporary workarounds for customers who can't patch straight away, including restricting the management console to a short list of trusted IP addresses.

Administrators can spot attempted attacks by watching their audit logs for the message "Administrator failed to log in: Username too long", which is what a failed exploit attempt leaves behind.

What about the other Check Point bugs?

Two other critical Check Point flaws were patched the week before, as we reported on 17 September, both rated 9.8. CVE-2026-85103 is a heap buffer overflow in the code that reads VPN certificates. CVE-2026-85102 bypasses certificate trust checks during a VPN handshake and allows remote code execution on the gateway.

The Dutch national cyber agency, NCSC-NL, has told Dutch organisations to treat both as urgent because it expects attacks soon.

Separately, two earlier Check Point authentication bypasses are already being used against real customers. CISA, which keeps an official list of bugs known to be under attack, added CVE-2026-50751 on 8 June with a federal patch deadline of 11 June, and CVE-2026-16232 on 22 July with a deadline of 25 July.

CVE What it hits Status
CVE-2026-91843 Security Management Server login Patched, not yet exploited
CVE-2026-85103 VPN certificate decoding Patched, not yet exploited
CVE-2026-85102 VPN certificate trust check Patched, not yet exploited
CVE-2026-16232 SmartConsole admin login Exploited, patch by 25 Jul
CVE-2026-50751 Gateway VPN authentication Exploited by Qilin affiliate

Who is Qilin and why does this matter?

Qilin is a ransomware crew: criminals who break into companies, steal data, scramble the originals and demand payment. First reported by BleepingComputer, one of its affiliates has been abusing the older Check Point bug since June to slip into corporate VPNs without credentials.

It's been a busy year for the group. Manufacturers are reportedly among its most common targets. The gang's claimed victims are published on leak sites, where criminals list companies they say they've hit. Those claims aren't confirmed breaches, but the volume tells you where the pressure is.

My read: Check Point admins have had a rough fortnight, and the broader pattern deserves attention. Edge devices with management consoles reachable from the open internet keep getting turned into ransomware entry points, and Qilin has clearly noticed. A perfect-score Cisco firewall management bug we covered the same day shows this isn't a Check Point problem alone. It's a category problem.

© 2026 Threat Vectr