Critical Stack Overflow Vulnerability in Check Point Security Management Servers Allows Root Code Execution Without Authentication
A critical stack overflow vulnerability (CVE-2026-91843) in Check Point Security Management and Log Servers allows unauthenticated attackers to execute root-level code via malicious login requests. Check Point has released a LivePatch fix, urging immediate application to prevent potential exploitation, though no active attacks have been reported yet.
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network.
The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw
*** END OF TRANSMISSION ***