Check Point Releases Security Advisory for Critical Vulnerability in Security Management and Log Servers
CVE-2026-91843 could allow unauthenticated remote code execution with root privileges on affected Check Point management systems
Summary
CVE-2026-91843 could allow unauthenticated remote code execution with root privileges on affected Check Point management systems
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Check Point has released security updates to address a critical vulnerability in Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server.
Successful exploitation could allow an unauthenticated remote attacker to run arbitrary code remotely with root privileges.
- CVE-2026-91843 - "Stack-based Buffer Overflow" vulnerability - CVSSv3.1 score: 9.8
Remediation advice
Affected organisations are encouraged to review Check Point advisory sk1000155, apply the relevant update as soon as possible, and implement the mitigation guidance within the advisory.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 17 September 2026 2:27 pm