Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Check Point flaw enables root code execution on management systems

According to BleepingComputer, Check Point Software has released security updates for a critical vulnerability that can let attackers execute code with root privileges on management systems. Tracked as CVE-2026-91843, the flaw is a stack-based buffer overflow in the login process for Security Management Server instances.

These systems manage Security Gateways and monitor network-security events. The issue also affects Check Point's Log Server, which collects and stores logs from Check Point firewalls. Successful exploitation can give attackers without privileges remote code execution through low-complexity attacks that require no user interaction.

Check Point said all Security Management Server deployments are vulnerable regardless of configuration. The company has not flagged CVE-2026-91843 as actively exploited, but said teams can look for “Administrator failed to log in: Username too long” alerts in Audit and Admin login logs.

For customers unable to deploy the latest LivePatch, Check Point listed temporary measures including hardening vulnerable systems and restricting access to trusted IP addresses or subnets through SmartConsole. Check Point also recently patched CVE-2026-85103, a critical remote-code-execution flaw affecting firewalls and management systems, and CVE-2026-85102, a critical authentication-bypass flaw that can enable remote code execution. The company said these vulnerabilities were not yet exploited in the wild.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.