Check Point has released an urgent security fix for a critical vulnerability that could allow attackers to remotely take control of some of its network management systems with the highest level of privileges.
The flaw, tracked as CVE-2026-91843, affects Check Point Security Management Servers and Log Servers. Check Point has assigned it a CVSS severity score of 9.8 out of 10, placing it firmly in the critical category.
The dangerous part is that attackers do not need an existing account or any interaction from a user. A successful attack could allow an unauthenticated intruder to execute arbitrary code remotely with root privileges.
Check Point says it has not seen evidence that the vulnerability is being exploited in real-world attacks so far. However, it is urging organisations to apply the available patch immediately because of the level of access an attacker could potentially gain.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
A login flaw can lead to complete server control
The vulnerability exists in the login process used by affected Check Point systems.
According to the technical description, it is caused by a stack-based buffer overflow. In simple terms, an attacker may be able to send specially crafted data that exceeds the amount of memory the programme expects to handle.
That memory corruption can then be abused to make the server execute commands chosen by the attacker.
The risk is particularly serious because the vulnerable systems are not ordinary employee computers. Security Management Servers are used to manage Check Point Security Gateways, including enterprise firewalls and security policies across an organisation’s network.
Log Servers, meanwhile, collect and store security logs generated by Check Point systems.
If attackers gain root access to such infrastructure, they may potentially reach a highly privileged position inside the organisation’s security environment. Root access is effectively the highest level of control on a Linux-based system.
What buffer overflow and root access actually mean
A buffer is a small area of computer memory set aside to hold data temporarily.
A buffer overflow happens when a programme receives more data than that space was designed to hold. Poorly handled overflow conditions can overwrite nearby memory and, in serious cases, allow an attacker to change how the programme behaves.
“Root” refers to the most powerful administrative account on many Unix and Linux systems.
An attacker operating as root may be able to install software, alter files, create accounts, disable security controls or interfere with other parts of the operating system.
That is why a vulnerability combining remote access, no authentication requirement and root-level execution is treated as particularly severe.
Check Point releases LivePatch and temporary protections
Check Point has released a LivePatch for CVE-2026-91843. Customers with automatic updates enabled may already have received the protection, according to the company’s advisory.
For organisations that cannot immediately install the patch, Check Point has also outlined temporary mitigation measures.
Administrators can restrict access to Security Management systems so that login attempts are accepted only from trusted IP addresses or approved network ranges. This reduces the number of systems capable of reaching the vulnerable service.
Security teams can also check logs for suspicious failed login attempts involving unusually long usernames. Check Point identified the alert “Administrator failed to log in: Username too long” as one possible sign of attempted exploitation.
Latest flaw follows a string of serious Check Point bugs
The disclosure comes only days after Check Point patched two other critical vulnerabilities affecting its VPN and security products.
Those flaws, CVE-2026-85102 and CVE-2026-85103, were both rated 9.8 and could allow unauthenticated remote attackers to execute code on affected gateways and management systems. European cybersecurity authorities urged organisations to patch them quickly because exploitation attempts were expected.
Check Point said those vulnerabilities had also been discovered internally and that there was no evidence of exploitation at the time of disclosure.
The company has faced real-world attacks against other flaws this year. BleepingComputer reported that CVE-2026-50751 was exploited by a Qilin ransomware affiliate, while another flaw, CVE-2026-16232, had been used to gain administrator access to SmartConsole systems.
That recent history makes rapid patching particularly important for organisations running internet-accessible Check Point infrastructure.
What this means for you: This vulnerability mainly affects organisations rather than ordinary home users. IT teams using Check Point Security Management or Log Servers should confirm that CVE-2026-91843 protections are installed and restrict management access to trusted networks wherever possible.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics