# Check Point warns of unauthenticated root flaw in management servers

_Published Saturday, September 19, 2026 at 8:20 AM EDT · Security · Latest · Tier 2 — Notable_

![Check Point warns of unauthenticated root flaw in management servers — Primary](https://heise.cloudimg.io/v7/_www-heise-de_/imgs/18/5/1/6/7/5/1/2/shutterstock_1861629355-9fc4ce677a187b30.jpg?func=bound&height=1200&org_if_sml=1&q=85&width=1200)

Check Point Security Management and Log Servers are exposed to a critical vulnerability, CVE-2026-91843, that can allow remote, unauthenticated code execution with root privileges, heise reported. The flaw is in the login process, where prepared requests with extremely long usernames can trigger memory errors. Check Point lists affected releases and provides repaired versions for supported products; Smart-1 Cloud is reported as already secured. The company has not indicated that the vulnerability is being actively exploited.

## Sources

- [heise.de](https://www.heise.de/en/news/Root-security-flaw-endangers-Check-Point-Security-Management-and-Log-Servers-11457980.html)

---
Canonical: https://techandbusiness.org/newswire/UZwVA0wU_JKb_rR8kyqE_j
Published: 2026-09-19T12:20:30.155Z
Story chronology: 2026-09-18T08:25:00.000Z
Retrieved: 2026-09-19T14:25:46.148Z
Publisher: Tech & Business (techandbusiness.org)
