Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
- ID
- 25848
- Status
- summarized
- Published
- 18 Sep 2026, 2:08 AM
- Fetched
- 18 Sep 2026, 12:41 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/critical-check-point-management-server.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 18 Sep 2026, 12:44 PM
- Tags
- Audience
- developers
What happened
A CVSS 9.8 stack overflow vulnerability (CVE-2026-91843) in Check Point Security Management and Log Servers allows unauthenticated remote attackers to execute code as root by sending a login request with a very long username. The flaw exists in the Trusted Clients login path, affects R82.10 (Jumbo Hotfix Take ≤44), R82 (≤126), and R81.20, and Check Point has shipped a LivePatch fix (advisory sk1000155) with no known exploitation in the wild as of September 17, 2026.
Why it matters
If your organization runs Check Point Security Management Servers, verify whether automatic LivePatch updates are enabled and confirm you are above the affected Jumbo Hotfix Take levels immediately. For most builders not managing Check Point infrastructure directly, this requires no action.
Discussion angle
Brief mention only: note that pre-authentication stack overflows in management planes remain a pattern worth watching, but this specific CVE is actionable only for teams operating Check Point firewalls.