Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
Check Point patched CVE-2026-91843 (CVSS 9.8), a pre-authentication stack overflow letting unauthenticated attackers run code as root on Security Management and Log Servers.
CVE-2026-91843 (CVSS 9.8) is a stack overflow in the pre-authentication login process of Check Point Security Management and Log Servers, reachable through the Trusted Clients setting. Check Point shipped a fix via LivePatch advisory sk1000155 and says there is no indication of exploitation; CISA also lists exploitation as none and no public PoC exists as of September 16. Affected branches span R80 through R82.20 (including end-of-support releases), and Censys observes 3,836 hosts presenting Check Point management identities. It is the fifth critical unauthenticated management flaw since July 22; the earlier SmartConsole bypass CVE-2026-16232 was exploited in July.