Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution
Check Point patched CVE-2026-91843 (CVSS 9.8), a pre-authentication root RCE in Security Management and Log Servers; no exploitation observed.
Check Point fixed CVE-2026-91843 (CVSS 9.8), an unauthenticated stack overflow in the Security Management and Log Server login process that enables remote code execution as root. The attack path requires the Trusted Clients setting governing SmartConsole access and affects versions from R80 through R82.20 below listed hotfix takes. The fix ships via LivePatch under advisory sk1000155; Censys observed 3,836 hosts with the management role and no public PoC as of September 16.