HomeSecurityCritical vulnerability in Check Point management allows code execution as Root

Critical vulnerability in Check Point management allows code execution as Root

A critical vulnerability in Check Point 's Security Management and Logging Servers could allow an attacker without login credentials to execute code as root on these servers over the network.

See also: Check Point reveals 2 VPN certificate flaws

Article Image: Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

The Security Management Server controls firewall policy and administrator access. Check Point has released a fix through the LivePatch and states that it has no indication that the vulnerability has been exploited. The vulnerable path is only executed through the Trusted Clients, which controls which computers can connect to the management server via SmartConsole.

The vulnerability, tracked as CVE-2026-91843 and rated 9.8 out of 10 on the CVSS scale by Check Point, is a stack overflow in the login process, which handles requests before the user is authenticated. Internet scanning firm Censys said the overflow is caused by a login request that has a very long username.

Check Point announced to the CheckMates community on September 16, 2026 that customers with automatic updates enabled are already protected and that others should apply the LivePatch fix described in advisory sk1000155. It urged customers to take immediate action due to the severity and potential impact of the vulnerability.

At this time, there is no indication that this vulnerability has been exploited in the wild,” the statement said. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed the exploit as “none” in its assessment attached to the CVE entry on Sept. 17.

The vulnerability was not on CISA's list of Known Exploited Vulnerabilities since the list was released on September 16. Censys reported that there was no public evidence of an exploit on September 16. Aviv Abramovich, vice president of product management for network security at Check Point, confirmed that the company had not received any reports of an exploit.

Check Point's CVE entry lists the following branches as affected, per Jumbo Hotfix Take, the numbered level of the update package that collects fixes for a release. A server on a listed branch in the listed Take or earlier is affected.

See also: Check Point VPN zero-day: How to protect your corporate VPN

Check Point vulnerability - SecNews.gr

Standalone installations, which run management and gateways on a system, Registry Servers and Multi-Domain servers are also vulnerable, Abramovich noted. A notice from NHS England Digital, citing sk1000155, says the hosted Smart-1 Cloud service is not affected because the fix is ​​already in place there.

The CVE entry notes that versions R81.10 and older branches are unsupported. Check Point has a fix ready for these unsupported versions, and customers who need it should file a request with Check Point support.

What Administrators Should Do:

Apply the LivePatch fix described in sk1000155 to each Security Management Server and Logging Server. If automatic updates are enabled, verify that the fix is ​​installed rather than assuming it is. The cplp list command shows which LivePatches are installed and their status.

Regardless of whether the fix is ​​installed, ensure that Trusted Clients' access to management is limited to known, trusted computers and is not set to any IP address, and do not expose management access directly to the internet.

Automatic Updates” refers to the setting described in sk175504, according to the Check Point hardening guide. It is the checkbox in SmartConsole, under General Properties and Data Access Control, labeled “Automatically download and install Blade Software Agreements, security updates, and other important data (highly recommended),” followed by the Access Control policy installation.

LivePatch is the channel that Check Point uses to push urgent security fixes to systems where this option is enabled.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Check Point: Critical VPN zero-day used by Qilin ransomware (update)

immediate update on Check Point VPN vulnerabilities

Delivery isn't always immediate. When Check Point pushed out fixes for two VPN certificate vulnerabilities last week, several customers reported to its community that the automatic package hadn't arrived on their systems on the day of the announcement.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS