New Check Point flaw lets hackers execute code with root privileges
PatchSecurity Management ServerLog ServerOur summary
Check Point has issued a LivePatch for CVE-2026-91843, a stack-based buffer overflow in the login process of Security Management Server that also affects Log Server. An unauthenticated attacker could exploit the flaw with low complexity to run code remotely with root privileges, and Check Point says all Security Management Server deployments are affected regardless of configuration. Organizations unable to deploy the update should apply the vendor's hardening guidance and restrict trusted client access; no active exploitation has been reported.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.