New Check Point flaw lets hackers execute code with root privileges

Cybersecurity firm Check Point has just released critical security updates to address a serious vulnerability that could allow hackers to execute code with root privileges on management systems. The issue, tracked as CVE-2026-91843, affects various Check Point products, including Security Management Server instances and the company’s Log Server.

The problem lies in a stack-based buffer overflow weakness in the login process for Security Management Server instances. These systems manage Security Gateways (firewalls) and monitor network security events. When exploited, the flaw allows attackers to gain root remote code execution without needing user interaction or privileges. This means that even if an attacker doesn’t have administrative access, they can still execute malicious code with full system privileges.

The vulnerability affects all Security Management Server deployments, regardless of their configuration. According to Check Point, “the management is vulnerable even when VPN in not in use or configured.” This broad impact is concerning, as it means that any organization using Check Point products could be at risk.

Successful exploitation can be detected by looking for specific error messages in the Audit and Admin login logs. However, it’s essential to note that Check Point has not yet reported any active exploitation of this flaw. Nevertheless, the company warns that other critical vulnerabilities have been exploited in recent months, including authentication bypass zero-days and remote code execution flaws.

To mitigate this issue, Check Point recommends deploying the latest security updates or applying temporary measures, such as hardening vulnerable systems against attacks and limiting access to trusted IP addresses/subnets. However, these workarounds are not a permanent solution and should be used only until the latest patches can be applied.

This is the third critical vulnerability reported by Check Point in recent months. Last week, the company patched another remote code execution flaw (CVE-2026-85103) affecting VPN certificate ASN.1 decoding flow. This highlights the importance of keeping software up to date and monitoring for potential security issues.

In practical terms, this means that organizations using Check Point products should prioritize patching as soon as possible to minimize their exposure to potential attacks. Additionally, it’s crucial to maintain a robust cybersecurity posture by regularly reviewing system configurations, monitoring logs, and implementing comprehensive security measures to prevent exploitation of known vulnerabilities.


Source: Bleeping Computer — 2026-09-18