Protect.Computer
NEWS

Critical Check Point Management Server Flaw Allows Root Code Execution

· 1 min read · Network safety
Critical Check Point Management Server Flaw Allows Root Code Execution

Check Point has patched a critical vulnerability in its Security Management Server that lets unauthenticated attackers execute arbitrary code with root privileges — no credentials, low complexity, no user interaction required. The flaw, CVE-2026-91843, is a stack-based buffer overflow in the login process for Security Management Server instances, which organizations use to manage their Check Point Security Gateway firewalls and monitor network events. The vulnerability also affects Check Point’s Log Server. “All Security Management Server deployments are vulnerable, regardless of configuration,” the company warned. “The vulnerability is not dependent on any specific management configuration. The management is vulnerable even when VPN is not in use or configured.”

Check Point has released a LivePatch to address the issue. For organizations that cannot immediately apply the patch, temporary mitigations include restricting access to the management server to trusted IP addresses and subnets — configured under Manage & Settings → Permissions & Administrators → Trusted Clients in the SmartConsole dashboard. CVE-2026-91843 is not yet flagged as actively exploited, but it follows two other critical Check Point flaws patched last week (CVE-2026-85102 and CVE-2026-85103, covering auth bypass and VPN certificate heap overflow respectively) that the Dutch National Cyber Security Centre has warned are at imminent risk of exploitation. Check Point has also seen active exploitation of two other management flaws in recent months — a Qilin ransomware affiliate abused CVE-2026-50751 since June, and CVE-2026-16232 has been exploited since July.

How to check if you’re affected

Affected products include Check Point Security Management Server and Log Server in all deployment configurations. Apply the latest LivePatch from the Check Point support portal immediately. If patching is delayed, restrict SmartConsole access to Trusted Clients (known IPs/subnets). Security teams can identify exploitation attempts by looking for Administrator failed to log in: Username too long alerts in SmartConsole’s Audit and Admin login logs.

Sources

Related reading