NewsTradingSentimentEventsCommunityBriefing
Tech

Check Point Patches Critical Root Access Flaw in Management Systems

By Tech Desk · 2026-09-20 · 2 min read
A glowing digital shield protecting a server rack
Illustration: Tradingbird

A critical vulnerability in Check Point's management software allows attackers to gain full system control without user interaction, prompting urgent security updates.

Check Point Software has issued urgent security updates to address a critical vulnerability that permits attackers to execute code with root privileges on its management systems. The flaw, identified as CVE-2026-91843, exists in the login process of the Security Management Server, which oversees network firewalls and monitors security events. Because the server operates with high-level permissions, a successful breach grants the attacker total control over the network infrastructure.

The vulnerability is a stack-based buffer overflow that can be exploited by unprivileged threat actors through low-complexity attacks. It does not require any user interaction, meaning the exploit can occur silently in the background. This issue also affects the company's Log Server, which collects and stores data generated by Check Point firewalls, expanding the scope of the potential damage.

Universal Risk Across All Deployments

Check Point emphasized that all Security Management Server deployments are vulnerable, regardless of their specific configuration. The company clarified that the flaw is not dependent on any particular management settings and persists even when Virtual Private Network features are not in use or configured. This means that organizations cannot simply disable certain features to mitigate the risk; they must apply the patch to secure the core system.

For customers who cannot immediately deploy the latest update, the vendor provided temporary mitigation steps. These include hardening the vulnerable systems and restricting access to trusted IP addresses by editing permissions within the SmartConsole dashboard. While these measures reduce the attack surface, they are not a permanent solution and require careful manual configuration to be effective.

Detecting Exploitation Attempts in Logs

Although Check Point has not flagged this specific flaw as actively exploited in the wild, it has provided security teams with a way to identify potential attacks. Administrators can look for specific alerts in the Audit and Admin login logs that read "Administrator failed to log in: Username too long." This distinct error message serves as a red flag that an attacker may have attempted to trigger the buffer overflow vulnerability.

The urgency of this patch is heightened by a recent trend of other critical flaws in the Check Point ecosystem. Last week, the company fixed another remote code execution vulnerability involving a heap overflow in VPN certificate handling. It also patched a second flaw that allowed unauthenticated hackers to bypass authentication entirely. While these specific CVEs are not yet known to be exploited, the pattern of severe bugs in the same product line raises concerns about the broader security posture.

Context of Recent Zero-Day Abuses

Check Point has acknowledged that other vulnerabilities in its software have been actively exploited by criminal groups in recent months. One authentication bypass zero-day was abused by a Qilin ransomware affiliate starting in June. Another similar flaw has been used since July to gain administrator privileges in SmartConsole panels. Additionally, the Dutch National Cyber Security Centre recently warned organizations to prioritize patching related VPN flaws, expecting exploitation attempts to occur soon.

Reporting by BleepingComputer highlights the ongoing pressure on enterprise security teams to keep pace with rapidly evolving threats. The combination of a critical root access bug and a history of exploited zero-days suggests that network managers must treat these updates as top priorities. Delaying the patch leaves organizations exposed to potential total network compromise, especially given that the attack vector requires no user interaction.

Based on reporting by BleepingComputer, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories