CVE-2026-91843
CVSS 9.8 CRITICAL: a stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with…
Vulnerabilities & Exploits
Check Point patched CVE-2026-91843, a critical stack overflow in the pre-auth Trusted Clients login path of its Security Management Server and Log Server that can let an unauthenticated attacker run code as root. Check Point says it has no indication of exploitation, and it has released LivePatch fixes for affected branches, including R82.20.
The bug sits before authentication: a login request with an overlong username can overflow memory in the management service’s login process. Because that process runs on the box that controls firewall policy and administrator access, root there means the attacker can take over the control plane, not just crash a service.
For shops that expose management interfaces to Trusted Clients hosts, the blast radius is the management plane itself, and that is what persists after the patch story is over: any host that can reach that front door inherits the risk until the exposure is closed off or updated. CISA lists no known exploitation so far, so this is a high-impact vulnerability, not an active-campaign report.
5 sources · 3 days ago
CVSS 9.8 CRITICAL: a stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with…
NCSC-NL Advisories
Kwetsbaarheid verholpen in Check Point's Security Management and Log Servers
Check Point heeft een kwetsbaarheid verholpen in Check Point's Security Management and Log Servers.
originalSecurityWeek
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.
originalBleepingComputer
New Check Point flaw lets hackers execute code with root privileges
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems.
originalPart of the PlainSec briefing for 2026-09-21
Every edition of this story: Check Point Login Overflow Reaches Root on Management Servers