ZeroHour
Product

Log Server

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Critical Check Point Vulnerability Allows Remote Root Code Execution Without Authentication

Check Point patched CVE-2026-91843 (CVSS 9.8), an unauthenticated stack overflow enabling remote root code execution on Security Management and Log Servers.

Check Point issued a high-severity alert for CVE-2026-91843, a critical stack overflow (CVSS 9.8, solution sk1000155) in the unauthenticated login workflow of Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server. Successful exploitation grants an unauthenticated remote attacker root-level code execution. Affected releases span R80 through R82.20 with Jumbo Hotfix takes at or below specified levels (e.g., R82.20 Take 44, R81.20 Take 166), with several older versions end of support. A LivePatch is available and offline urgent bundles (R81.20-R82.20 Takes 28-29) were released; Smart-1 Cloud is already protected.

Check Point Vulnerability Lets Remote Hackers Gain Root Access Without Authentication

Check Point patched CVE-2026-91843, a CVSS 9.8 pre-auth stack overflow granting remote root on Security Management and Log Servers.

Check Point released an urgent fix for CVE-2026-91843 (CVSS 3.1: 9.8), a stack-based buffer overflow triggered by an excessively long username during login that lets an unauthenticated remote attacker execute arbitrary code with root privileges. Affected products include Security Management Server, Multi-Domain Security Management Server, and Log Servers across releases from R80 through R82.20, with fixes delivered via LivePatch and urgent Take packages. The vendor reports no observed exploitation in the wild, and administrators are advised to verify patch deployment and restrict SmartConsole Trusted Clients.

Cyber Security Newsupdated · 7h agofirst · 19h agoVulnerability 8 sourcesCVE-2026-91843

Related CVEs

  • Unauthenticated stack overflow gives root RCE in Check Point login process
    CVE-2026-91843 is a stack-based buffer overflow (CWE-121) in the unauthenticated login process of a Check Point product, as Check Point Software ([email protected]) is the assigning CNA and its CVE scope covers Check Point products. An attacker can trigger the flaw remotely by sending crafted input to the login interface before authenticating, with no user interaction or credentials required. Successful exploitation allows arbitrary code execution with root privileges, the highest level of control on the affected system. The vulnerability is rated 9.8 Critical (AV:N/AC:L/PR:N/UI:N, all impacts high), reflecting trivial network exploitability. No public proof-of-concept or confirmed in-the-wild exploitation is known at this time, and the source data does not name the specific product line or affected version ranges.
    · Check Point

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.