Critical Check Point bug grants unauthenticated root access to management servers

Check Point Software patched a critical stack-based buffer overflow in its Security Management Server and Log Server, tracked as CVE-2026-91843, that allows unprivileged attackers to achieve remote code execution with root privileges in low-complexity attacks. The vendor provided temporary mitigations for customers unable to apply the LivePatch, including restricting access to trusted IP addresses. While no active exploitation has been reported, administrators can detect attempts by monitoring for specific login failure alerts in the Audit and Admin logs.
The vulnerability affects both Security Management Server and Log Server deployments, with Check Point noting that all management server installations are vulnerable regardless of configuration. The flaw exists in the login process, where an overly long username triggers a stack-based buffer overflow. Administrators can detect potential attacks by monitoring Audit and Admin logs for specific login failure alerts.
Check Point has also released LivePatch updates for customers, alongside guidance for restricting access to trusted IP addresses as a temporary workaround. This follows a series of recent critical patches from the vendor, including two VPN-related flaws disclosed last week that the Dutch NCSC expects to be exploited soon.
This vulnerability could have significant consequences for organizations relying on Check Point management infrastructure, as successful exploitation grants root-level access to systems that oversee firewall operations. If exploited, attackers could potentially disable security controls, alter firewall rules, or exfiltrate sensitive network data. Given the vendor's recent history of zero-day exploitation by ransomware affiliates, security teams may face increased pressure to prioritize patching. However, the lack of confirmed active exploitation and available mitigations may provide some window for organizations to secure their systems.