Check Point Management Flaw Allows Root Access

A critical security gap in Check Point's management infrastructure allows unauthenticated attackers to execute code with root privileges. The company has issued an urgent patch, though the trade-off is that many organizations must manually verify their update status to ensure protection.
A critical vulnerability in Check Point's Security Management and Log Servers exposes a dangerous pathway for attackers. This flaw, identified as CVE-2026-91843, permits an individual without any login credentials to execute code with root privileges over the network. Because the Security Management Server controls firewall policies and administrator access, a compromise here effectively grants an attacker total control over the network's security perimeter.
Check Point has released a fix through its LivePatch update channel and states there is no evidence the flaw has been exploited in the wild. However, the company urges immediate action due to the severity of the risk. The vulnerability stems from a stack overflow in the login process, triggered by a login request containing an unusually long username. This occurs before user authentication, meaning no valid account is needed to trigger the crash and subsequent code execution.
The Risk of Unauthenticated Access
The threat is particularly acute because the vulnerable code path is accessible through the Trusted Clients setting. This setting determines which hosts can connect to the management server via SmartConsole. If an administrator has configured this setting to accept connections from any IP address, the server becomes highly exposed to internet scanning bots and opportunistic attackers. Censys, an internet scanning company, confirmed that the overflow is triggered simply by sending a long username in a login request.
Aviv Abramovich, vice president of product management for network security at Check Point, told The Hacker News that the company has not received any reports of active exploitation. The U.S. Cybersecurity and Infrastructure Security Agency also recorded exploitation as none in its assessment. Despite this lack of confirmed attacks, the high CVSS score of 9.8 out of 10 highlights the potential for severe damage if the flaw is discovered and used by a malicious actor.
Which Systems Are Vulnerable
The vulnerability affects a wide range of Check Point versions, including R82.10, R82, R81.20, and R81.10, among others. Specifically, systems running Jumbo Hotfix Take 44 or below on R82.10 are at risk. Notably, R82.20 is also vulnerable, and according to Censys, every build of this branch is affected with no current Jumbo Hotfix providing protection. Standalone deployments, Log Servers, and Multi-Domain servers are also impacted.
Older versions like R81.10 and R80 are marked as end-of-support, but Check Point has prepared a fix for these as well. Customers using these legacy systems must contact support directly to obtain the patch. NHS England Digital noted that the hosted Smart-1 Cloud service is not affected because the fix is already in place there, highlighting a key difference between self-managed and cloud-hosted deployments.
Steps for Immediate Remediation
Administrators should apply the LivePatch fix described in advisory sk1000155 to all affected Security Management and Log Servers. For those with automatic updates enabled, it is crucial to verify that the patch has actually installed rather than assuming it did. The cplp list command can be used to check which LivePatches are present and their status.
Regardless of the patch status, organizations must review their Trusted Clients configuration. Access should be restricted to known, trusted hosts, and management access should never be exposed directly to the internet. This dual approach of patching and network hardening provides the most robust defense against this critical flaw. The trade-off is the administrative effort required to audit configurations and apply updates, but it is necessary to prevent a potential total network compromise.






