CVE-2026-91843: A critical RCE flaw affecting Check Point Security Management and Log Servers
18 Sep 2026
Check Point recently disclosed a critical stack-based overflow/remote code execution flaw in its Security Management and Log Servers. The vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges.
It is particularly dangerous because it requires no prior privileges or user interaction.
Through this blog, we will understand what the vulnerability is about, the threat it poses, and what organizations can do to defend against the vulnerability.
About the vulnerabilities
|
Vendor/ Component impacted |
Threat Type |
CVE identifier/ CVSS |
Affected products |
|
Check Point / Security Management and Log Server |
Remote Code Execution/ Stack-based Buffer Overflow |
CVE-2026-91843/ 9.8 (Critical)
|
|
The threat posed by the vulnerability
When successfully weaponized, the RCE flaw can allow an attacker to:
- Execute arbitrary code with root-level privileges.
- Cause the compromise of the Check Point Security Management or Log Server.
- Modify security management configurations and trusted administrative settings.
- Gain access to sensitive management and security information.
- Potentially use a compromised management server as a platform for further compromise of the security environment.
A Check Point management server can give an attacker control or visibility over many security devices. So, even if it is just a single machine, the potential consequences can extend beyond a particular server.
Official security guidance
Check Point recommends applying the LivePatch fix described in sk1000155. Customers with automatic security updates enabled may already be protected.
As an additional mitigation, Check Point recommends following its Gateway and Management Hardening guidance and restricting management Trusted Clients access to known, specific internal IP addresses.
SharkStriker’s recommendations
- Apply the Check Point LivePatch immediately as described in sk1000155 and verify that the fix has been successfully applied.
- Restrict SmartConsole Trusted Clients to only the required administrative IP addresses, subnets, or jump hosts. Avoid broad access such as Any where it is not operationally required. Check Point’s hardening guide specifically recommends minimizing Trusted Client access.
- Place Security Management Servers in a protected management segment behind a firewall and restrict administrative access to dedicated management networks or jump hosts.
- Enforce MFA for administrative access and remove unused or unnecessary administrator accounts. Check Point recommends MFA for administrative roles and regular review of administrator accounts.
- Maintain the latest supported Check Point Hotfix/Jumbo Hotfix level and review the management-plane hardening configuration periodically to reduce unnecessary exposure.
SharkStriker’s actions
SharkStriker has reviewed the Check Point security notification and associated hardening guidance for CVE-2026-91843.
Our SOC teams are assessing relevant Check Point telemetry and detection opportunities associated with potential compromise of Security Management and Log Servers. Customers should prioritize verification of the affected management assets, LivePatch status, Trusted Client configuration, and administrative access controls.