New Check Point Flaw Lets Hackers Execute Code with Root Privileges
Bleeping Computer, Friday, September 18th, 2026
BleepingComputer reports Check Point patched CVE-2026-91843, a critical pre-auth bug giving root code execution on management servers.
BleepingComputer reports that Check Point has issued security updates for CVE-2026-91843, a critical stack-based buffer overflow in the login process of its Security Management Server and Log Server products.
Because the flaw sits in pre-authentication code, an unauthenticated attacker who can reach the management plane could execute arbitrary code with root privileges on the system that controls firewall policy and administrator access.
Security Management Servers manage Security Gateways and collect network security events, making them a high-value target. Check Point is pushing the fix through its LivePatch channel and urging customers without automatic updates to patch immediately.