CVE-2026-91843: A critical RCE flaw affecting Check Point Security Management and Log Servers

18 Sep 2026

Check Point recently disclosed a critical stack-based overflow/remote code execution flaw in its Security Management and Log Servers. The vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges.

 

It is particularly dangerous because it requires no prior privileges or user interaction.

 

Through this blog, we will understand what the vulnerability is about, the threat it poses, and what organizations can do to defend against the vulnerability.

About the vulnerabilities

Vendor/ 

Component impacted 

Threat Type 

CVE identifier/ CVSS 

Affected products 

Check Point / Security Management and Log Server 

Remote Code Execution/ Stack-based Buffer Overflow 

CVE-2026-91843/ 9.8 (Critical) 

 

  • R82.10 with Jumbo Hotfix Take 44 or below 
  • R82 with Jumbo Hotfix Take 126 or below 
  • R81.20 with Jumbo Hotfix Take 166 or below 
  • R81.10 with Jumbo Hotfix Take 190 or below 
  • R81 and earlier supported branches identified by Check Point as affected 

The threat posed by the vulnerability

When successfully weaponized, the RCE flaw can allow an attacker to:

 

  • Execute arbitrary code with root-level privileges.
  • Cause the compromise of the Check Point Security Management or Log Server.
  • Modify security management configurations and trusted administrative settings.
  • Gain access to sensitive management and security information.
  • Potentially use a compromised management server as a platform for further compromise of the security environment.

 

A Check Point management server can give an attacker control or visibility over many security devices. So, even if it is just a single machine, the potential consequences can extend beyond a particular server.

Official security guidance

Check Point recommends applying the LivePatch fix described in sk1000155. Customers with automatic security updates enabled may already be protected.

 

As an additional mitigation, Check Point recommends following its Gateway and Management Hardening guidance and restricting management Trusted Clients access to known, specific internal IP addresses.

SharkStriker’s recommendations

  • Apply the Check Point LivePatch immediately as described in sk1000155 and verify that the fix has been successfully applied.
  • Restrict SmartConsole Trusted Clients to only the required administrative IP addresses, subnets, or jump hosts. Avoid broad access such as Any where it is not operationally required. Check Point’s hardening guide specifically recommends minimizing Trusted Client access.
  • Place Security Management Servers in a protected management segment behind a firewall and restrict administrative access to dedicated management networks or jump hosts.
  • Enforce MFA for administrative access and remove unused or unnecessary administrator accounts. Check Point recommends MFA for administrative roles and regular review of administrator accounts.
  • Maintain the latest supported Check Point Hotfix/Jumbo Hotfix level and review the management-plane hardening configuration periodically to reduce unnecessary exposure.

SharkStriker’s actions

SharkStriker has reviewed the Check Point security notification and associated hardening guidance for CVE-2026-91843.

 

Our SOC teams are assessing relevant Check Point telemetry and detection opportunities associated with potential compromise of Security Management and Log Servers. Customers should prioritize verification of the affected management assets, LivePatch status, Trusted Client configuration, and administrative access controls.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE