Threat Intelligence

Critical Check Point Flaw Lets Attackers Take Over Management Servers Without Logging In

The Hacker News · 18 Sept 2026
Key Takeaway If your business uses Check Point Security Management or Log Servers, confirm automatic updates are enabled or apply the LivePatch fix from advisory sk1000155 without delay.

Check Point has disclosed a critical vulnerability, CVE-2026-91843, in its Security Management and Log Servers that could allow an attacker without any login credentials to run code as root over the network. The Security Management Server controls firewall policy and administrator access, making it a high-value target. The flaw is a stack overflow in the login process, triggered before a user is authenticated, and is only reachable through the Trusted Clients setting that controls which hosts can connect via SmartConsole.

Check Point rated the flaw 9.8 out of 10 on the CVSS scale and released a fix through its LivePatch update channel. Customers with automatic updates enabled are already protected; others should apply the fix described in advisory sk1000155 as soon as possible. Several product branches are affected depending on their Jumbo Hotfix level, and Check Point confirmed that the R82.20 branch is vulnerable in every build, with no Jumbo Hotfix yet available to protect it.

As of publication, Check Point, CISA, and internet scanning firm Censys all reported no evidence of exploitation in the wild, and no public proof-of-concept exploit was known to exist. Still, given the severity of the flaw and the sensitive role these servers play in managing firewall security, Check Point has urged all affected customers to act immediately.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.