Check Point patches critical login flaw that hands attackers root on firewall management servers
CVE-2026-91843 is the third critical bug in a fortnight for Check Point, and two earlier authentication bypasses are already being exploited in the wild.

Key points
- Check Point has patched CVE-2026-91843, a critical flaw scored 9.8 out of 10 that lets an attacker with no password take full control of the server running a company's firewalls.
- The bug affects Security Management Server and Log Server systems, the machines that run and record activity for Check Point firewalls.
- Two earlier Check Point authentication bypasses, CVE-2026-50751 and CVE-2026-16232, are already being attacked, with US federal agencies ordered to patch them by 11 June and 25 July 2026 respectively.
- One of those active attacks is being run by an affiliate of the Qilin ransomware gang, which breaks into companies, steals files and encrypts the originals.
- This is the ninth Check Point story we've published since 30 June, and the pattern is not getting better.
Check Point, one of the biggest sellers of corporate firewalls, has released an emergency fix for a flaw that lets a stranger on the internet take over the server controlling a company's entire firewall estate.
The bug is tracked as CVE-2026-91843 and carries a severity score of 9.8 out of 10. It sits in the login screen of Check Point's Security Management Server, the central console administrators use to run their firewalls. A firewall is the piece of network equipment that decides what traffic is allowed in and out of a company's network.
The flaw is a stack-based buffer overflow, a very old class of programming bug where sending an over-long input tricks the software into running the attacker's own commands. Those commands run as root, the highest level of access a system can grant. No password required, no click needed from any user. Check Point's Log Server, which stores records of firewall activity, is affected as well.
Is this being exploited in the wild?
Not yet, according to Check Point. The company has published the patch alongside temporary workarounds for customers who can't patch straight away, including restricting the management console to a short list of trusted IP addresses.
Administrators can spot attempted attacks by watching their audit logs for the message "Administrator failed to log in: Username too long", which is what a failed exploit attempt leaves behind.
What about the other Check Point bugs?
Two other critical Check Point flaws were patched the week before, as we reported on 17 September, both rated 9.8. CVE-2026-85103 is a heap buffer overflow in the code that reads VPN certificates. CVE-2026-85102 bypasses certificate trust checks during a VPN handshake and allows remote code execution on the gateway.
The Dutch national cyber agency, NCSC-NL, has told Dutch organisations to treat both as urgent because it expects attacks soon.
Separately, two earlier Check Point authentication bypasses are already being used against real customers. CISA, which keeps an official list of bugs known to be under attack, added CVE-2026-50751 on 8 June with a federal patch deadline of 11 June, and CVE-2026-16232 on 22 July with a deadline of 25 July.
| CVE | What it hits | Status |
|---|---|---|
| CVE-2026-91843 | Security Management Server login | Patched, not yet exploited |
| CVE-2026-85103 | VPN certificate decoding | Patched, not yet exploited |
| CVE-2026-85102 | VPN certificate trust check | Patched, not yet exploited |
| CVE-2026-16232 | SmartConsole admin login | Exploited, patch by 25 Jul |
| CVE-2026-50751 | Gateway VPN authentication | Exploited by Qilin affiliate |
Who is Qilin and why does this matter?
Qilin is a ransomware crew: criminals who break into companies, steal data, scramble the originals and demand payment. First reported by BleepingComputer, one of its affiliates has been abusing the older Check Point bug since June to slip into corporate VPNs without credentials.
It's been a busy year for the group. Manufacturers are reportedly among its most common targets. The gang's claimed victims are published on leak sites, where criminals list companies they say they've hit. Those claims aren't confirmed breaches, but the volume tells you where the pressure is.
My read: Check Point admins have had a rough fortnight, and the broader pattern deserves attention. Edge devices with management consoles reachable from the open internet keep getting turned into ransomware entry points, and Qilin has clearly noticed. A perfect-score Cisco firewall management bug we covered the same day shows this isn't a Check Point problem alone. It's a category problem.



