Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution
Brief
Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed.
Check Point addressed CVE-2026-91843 (CVSS score of 9. 8), a critical vulnerability in its Security Management and Log Servers. The flaw could let an attacker with no account run code as root over the network.
The flaw sits in the login process before authentication. Censys researchers found that an attacker can trigger the stack overflow by sending a login request with an extremely long username.
“This vulnerability may allow an unauthenticated attacker to remotely execute arbitrary code with root privileges through the login process.” reads the advisory . “At this time, there is no indication that this vulnerability has been exploited in the wild .
