AI & TechCybersecurityNewswireTechnologyWhat's Buzzing

Check Point Flaw Allows Root Code Execution

▼ Summary

– Check Point Software has released security updates to address CVE-2026-91843, a critical vulnerability allowing root remote code execution on management systems.
– The flaw involves a stack-based buffer overflow in the login process affecting Security Management Server and Log Server instances.
– Temporary mitigation measures include hardening systems and restricting access to trusted IP addresses via the SmartConsole dashboard.
– This release follows recent patches for other critical flaws like CVE-2026-85103 and CVE-2026-85102, which were flagged as high-risk by security centers.
– While not yet actively exploited, previous Check Point vulnerabilities have been abused by groups such as Qilin ransomware affiliates.

Check Point Software has issued urgent security patches to resolve a severe vulnerability that enables attackers to achieve root code execution on management systems. Identified as CVE-2026-91843, this critical flaw originates from a stack-based buffer overflow within the login mechanism of the Security Management Server. These servers are central to managing Security Gateways and monitoring network security events across an organization’s infrastructure.

The vulnerability also compromises the company’s Log Server, a dedicated appliance responsible for collecting and storing audit logs generated by Check Point firewalls. Exploitation of this weakness allows unprivileged threat actors to gain full root access with minimal effort. The attack requires no user interaction and is classified as low-complexity, making it particularly dangerous for organizations relying on these systems for network defense.

Immediate Mitigation Strategies

For customers unable to deploy the latest LivePatch immediately, Check Point has outlined temporary mitigation steps. Administrators should harden vulnerable systems against potential attacks and restrict access to only trusted IP addresses or subnets. This can be achieved by editing specific entries under Manage & Settings > Permissions & Administrators > Trusted Clients within the SmartConsole dashboard.

While the vendor has not confirmed active exploitation of CVE-2026-91843 in the wild, it advises security teams to monitor their environments for specific indicators of compromise. Attackers can be identified by searching for “Administrator failed to log in: Username too long” alerts within the Audit and Admin login logs. This signature suggests an attempt to trigger the buffer overflow through excessively long username inputs.

“All Security Management Server deployments are vulnerable, regardless of configuration,” Check Point warned. “The vulnerability is not dependent on any specific management configuration. The management is vulnerable even when VPN in not in use or configured.”

Recent Patch Cycle Context

This release follows a rapid succession of other critical updates last week. Check Point previously addressed CVE-2026-85103, another critical remote code execution flaw stemming from a heap overflow in the VPN certificate ASN.1 decoding flow. That same day, the company patched CVE-2026-85102, a vulnerability allowing unauthenticated hackers to bypass authentication and execute code remotely on vulnerable firewalls.

Although these specific flaws are not yet being actively exploited, Check Point has flagged other recent vulnerabilities as high-risk due to real-world abuse. An authentication bypass zero-day (CVE-2026-50751) has been leveraged by a Qilin ransomware affiliate since June. Additionally, another authentication bypass zero-day (CVE-2026-16232) has been exploited since at least July to grant administrator privileges to SmartConsole admin panels.

The urgency of patching is further emphasized by warnings from the Dutch National Cyber Security Centre (NCSC-NL). The agency recently urged organizations to prioritize fixing CVE-2026-85102 and CVE-2026-85103, stating that it “expects exploitation attempts to occur soon” given the severity and accessibility of these flaws.

(Source: BleepingComputer)

Topics

critical vulnerabilities 95% software patching 90% attack mitigation 85% ransomware threats 80% cybersecurity advisories 75%
Show More