Skip to main content

Check Point Releases Security Advisory for Critical Vulnerability in Security Management and Log Servers

CVE-2026-91843 could allow unauthenticated remote code execution with root privileges on affected Check Point management systems

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

CVE-2026-91843 could allow unauthenticated remote code execution with root privileges on affected Check Point management systems


Threat details

Introduction

Check Point has released security updates to address a critical vulnerability in Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server.

Successful exploitation could allow an unauthenticated remote attacker to run arbitrary code remotely with root privileges.

  • CVE-2026-91843 - "Stack-based Buffer Overflow" vulnerability - CVSSv3.1 score: 9.8

Remediation advice

Affected organisations are encouraged to review Check Point advisory sk1000155, apply the relevant update as soon as possible, and implement the mitigation guidance within the advisory.


Definitive source of threat updates


Last edited: 17 September 2026 2:27 pm