PT-2026-93729 · Check Point · Dell Security Management Server+3

CVE-2026-91843

·

Published

2026-09-16

·

Updated

2026-10-02

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Check Point Security Management Server (affected versions not specified) Check Point Multi-Domain Security Management (affected versions not specified) Check Point Log Server (affected versions not specified)
Description A stack-based buffer overflow exists in the login process of Security Management, Multi-Domain, and Log Servers. This flaw occurs before authentication, meaning security measures such as multi-factor authentication (MFA), password policies, and account lockouts are bypassed. An unauthenticated remote attacker can exploit this by sending a crafted payload with an oversized username to the management port (typically TCP 443 / Gaia Portal), allowing them to execute arbitrary code with root privileges. This affects all Security Management Server deployments regardless of VPN configuration. Potential exploitation can be identified in audit and admin login logs by the message "Administrator failed to log in: Username too long".
Recommendations Apply the official LivePatch provided by Check Point via Central Deployment or CPUSE. Restrict access to the Gaia portal and management ports to trusted internal management subnets, jump boxes, or authenticated VPN tunnels, ensuring they are not exposed to the public internet. Limit SmartConsole Trusted Clients to the minimum required IP addresses, subnets, or ranges, and remove any entries with a client type of Any. Verify the protection status by running cplp list in Expert mode to ensure fwm:fwm is armed against the issue.

Exploit

Fix

RCE

DoS

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14921
CVE-2026-91843

Affected Products

Check Point Gaia
Klog Server
Multi-Domain Security Management
Dell Security Management Server