New Check Point flaw lets hackers execute code with root privileges

Check Point’s Management Systems Left Vulnerable to Root Privilege Attacks

A critical vulnerability in Check Point’s management systems has been discovered, allowing hackers to execute code with root privileges. This means that attackers can gain complete control over affected systems, potentially leading to widespread damage and data breaches.

The flaw, tracked as CVE-2026-91843, affects Check Point’s Security Management Server instances, which manage firewalls and monitor network security events. It also impacts the company’s Log Server, a dedicated server responsible for collecting and storing logs generated by Check Point firewalls. Successful exploitation of this vulnerability requires no user interaction, making it particularly concerning.

According to Check Point, all Security Management Server deployments are vulnerable, regardless of configuration. This means that even if VPNs are not in use or configured, the management systems can still be compromised. The company has released security updates to address this issue and recommends that customers deploy the latest LivePatch as soon as possible. In the meantime, it has provided temporary mitigation measures for those who cannot update their systems immediately.

Hardening vulnerable systems against attacks is one of these measures, which involves limiting access to trusted IP addresses or subnets by editing entries in the SmartConsole dashboard. Check Point also suggests looking out for specific alerts in the Audit and Admin login logs, such as “Administrator failed to log in: Username too long,” to identify potential CVE-2026-91843 attacks.

This vulnerability is not an isolated incident; Check Point has recently patched several other critical flaws affecting its products. Last week, it addressed a heap overflow in the VPN certificate ASN.1 decoding flow that affects firewalls and management systems (CVE-2026-85103). Another flaw (CVE-2026-85102) allows unauthenticated hackers to bypass authentication and execute code remotely on vulnerable firewalls.

While these vulnerabilities are not yet exploited in the wild, it’s essential for organizations using Check Point products to take this threat seriously. The Dutch National Cyber Security Centre has warned that exploitation attempts may occur soon, emphasizing the need for prioritized patching of CVE-2026-85102 and CVE-2026-85103.

In light of these vulnerabilities, we advise organizations to review their security configurations and ensure they are up-to-date with the latest patches. Regular monitoring of system logs and alerts can also help detect potential attacks.


Source: Bleeping Computer — 2026-09-18