Critical Check Point flaw allows unauthenticated remote code execution as root

Check Point Software disclosed CVE-2026-91843, a pre-authentication stack overflow vulnerability (CVSS 9.8) in Security Management servers enabling unauthenticated attackers to execute code with root privileges. The flaw affects management and log servers with no known active exploitation as of 2026-09-18.

7 reportsother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

🤖 CVE-2026-91843 (CVSS 9.8): pre-auth stack overflow in Check Point Security Management login process lets unauthenticated attackers run code as root on management/log servers. Fifth critical unauthe

mastodon:infosec-exchangeother11d ago kagi ↗

🤖 CVE-2026-91843 (CVSS 9.8): pre-auth stack overflow in Check Point Security Management login process lets unauthenticated attackers run code as root on management/log servers. Fifth critical unauthenticated management flaw since July. LivePatch fix out; restrict Trusted Clients. 🔗 https:// thehackernews.com/2026/09/crit ical-check-point-management-server.html # CVE # InfoSec # CyberSec

Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. https://www. bleepingcomputer.com

mastodon:infosec-exchangeother11d ago kagi ↗

Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. https://www. bleepingcomputer.com/news/secu rity/check-point-warns-critical-flaw-lets-hackers-execute-code-as-root/

🚨 SIGINT // Cybersecurity Watch — 2026-09-19 Critical Check Point Management Server flaw lets unauthenticated attackers run code as root. No known exploitation yet — patch now. https:// thehackernews

mastodon:fosstodonother11d ago kagi ↗

🚨 SIGINT // Cybersecurity Watch — 2026-09-19 Critical Check Point Management Server flaw lets unauthenticated attackers run code as root. No known exploitation yet — patch now. https:// thehackernews.com/2026/09/crit ical-check-point-management-server.html # CVE # InfoSec # Cybersecurity