New Check Point flaw lets hackers execute code with root privileges

Summary: Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. [...]

Check Point has released security updates for a critical vulnerability that could allow unauthenticated attackers to remotely execute code with root privileges on vulnerable management systems.

Tracked as CVE-2026-91843, the vulnerability affects Check Point Security Management Server and Log Server deployments. The issue originates from a stack-based buffer overflow in the login process used by Security Management Server, which plays a central role in managing Security Gateways and monitoring network security events.

Successful exploitation could give an attacker complete control over the affected system without requiring existing privileges or user interaction. Check Point describes the attack complexity as low, making patching particularly important for organizations operating exposed or accessible management infrastructure.

All Management Deployments Are Vulnerable

One of the most significant aspects of CVE-2026-91843 is that exposure does not depend on a particular management configuration.

Check Point warns that all Security Management Server deployments are vulnerable regardless of whether VPN functionality is configured or being used. The company’s Log Server, responsible for collecting and storing firewall logs, is also affected.

Check Point has released a LivePatch to address the vulnerability. Organizations unable to immediately deploy it can reduce their exposure by hardening affected systems and restricting management access to trusted IP addresses or subnets through SmartConsole’s Trusted Clients configuration.

Administrators should also review their logs for potential exploitation attempts. Check Point says attacks targeting the flaw can generate an alert containing:

Administrator failed to log in: Username too long

The message can appear in Audit and Admin login logs. However, Check Point has not currently classified CVE-2026-91843 as being actively exploited in the wild.

Check Point Faces a Series of Critical Vulnerabilities

The disclosure comes shortly after Check Point patched two additional critical remote code execution vulnerabilities.

CVE-2026-85103 involves a heap overflow in VPN certificate ASN.1 decoding and can affect Security Gateways and Security Management Servers.CVE-2026-85102 can allow an unauthenticated attacker to bypass authentication and remotely execute code on vulnerable firewalls.

The Dutch National Cyber Security Centre recently urged organizations to prioritize those patches, warning that exploitation attempts were expected soon.

Check Point has also dealt with vulnerabilities that attackers have already exploited during 2026. An authentication bypass tracked as CVE-2026-50751 was used by a Qilin ransomware affiliate, while another zero-day,CVE-2026-16232, has been exploited to obtain administrator-level access to SmartConsole.

Why the Vulnerability Is Particularly Dangerous

Management servers occupy a highly privileged position inside enterprise security infrastructure. Compromising one can potentially provide attackers with access to sensitive configuration information and security telemetry while creating opportunities to interfere with the systems responsible for protecting the network.

The ability to obtain root-level remote code execution therefore makes CVE-2026-91843 substantially more serious than a vulnerability affecting an ordinary endpoint.

Organizations using Check Point management infrastructure should prioritize the available LivePatch and restrict management interfaces to trusted networks wherever possible. Security teams should also examine authentication logs for suspicious oversized username attempts that could indicate attempts to exploit the vulnerability.

With multiple critical Check Point vulnerabilities disclosed in a short period, keeping gateways and their management infrastructure patched has become particularly important for organizations relying on the platform for perimeter security.

Key facts

  • Check Point Software has released security updates
  • The updates address a critical vulnerability
  • The flaw allows attackers to execute code with root privileges
  • The vulnerability affects management systems

Why it matters

This vulnerability poses a significant risk to organizations relying on Check Point's security solutions. Successful exploitation could grant attackers complete control over critical security infrastructure, enabling them to disable defenses, steal sensitive data, or pivot to other parts of a network. Prompt patching is essential to prevent widespread compromise.