CVE Tools

New Check Point flaw lets hackers execute code with root privileges

BleepingComputerBy Sergiu Gatlan

PatchSecurity Management ServerLog Server

Our summary

Check Point has issued a LivePatch for CVE-2026-91843, a stack-based buffer overflow in the login process of Security Management Server that also affects Log Server. An unauthenticated attacker could exploit the flaw with low complexity to run code remotely with root privileges, and Check Point says all Security Management Server deployments are affected regardless of configuration. Organizations unable to deploy the update should apply the vendor's hardening guidance and restrict trusted client access; no active exploitation has been reported.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store