Check Point Releases Fix for Critical Flaw Allowing Remote Code Execution as Root

The CVE-2026-91843 vulnerability in Security Management and Log Server products has a CVSS score of 9.8. Check Point released a fix through LivePatch and recommends deploying it immediately.

Check Point CVE-2026-91843 is a critical vulnerability in Security Management and Log Server products for which the vendor has released a fix through LivePatch. The flaw has a CVSS rating of 9.8 and, according to Check Point, could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.

The problem is located in the unauthenticated login process and is a stack-based buffer overflow. Check Point recommends that organizations apply the available fix without delay.

Who Is Affected by CVE-2026-91843

According to an NHS England alert, the affected platforms include Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server. According to the institution, the Smart-1 Cloud service is not affected.

These systems are used to manage security policies, administer security gateways, and work with logs. Their compromise could therefore provide an attacker with root access to a management or logging server without prior authentication.

LivePatch Fix and Temporary Access Restriction

Check Point has made a remediation available through LivePatch. Operators of affected systems should verify that the fix is deployed and working in their environment.

If an organization cannot apply LivePatch immediately, the vendor lists a temporary risk mitigation: restrict access to the affected systems to trusted IP addresses or subnets only. This measure does not replace the fix, but it may reduce the range of systems from which the login process is accessible.

  • Verify whether the organization operates any of the affected management or logging servers.
  • Check the status and availability of LivePatch for the specific deployment.
  • If the fix is not yet possible, restrict network access to trusted addresses or subnets.

No Confirmed Exploitation So Far

At the time of disclosure, Check Point stated that it had no information about exploitation of the vulnerability in the wild. However, this statement alone is not independent confirmation that exploitation has not occurred.

It is also not known how many unpatched installations are accessible from the internet. Further developments will show whether active exploitation is confirmed by the vendor or independent security teams, whether CVE-2026-91843 appears in CISA’s Known Exploited Vulnerabilities catalog, and whether the affected versions—including the availability of fixes for systems that have reached end of support—are clarified.

Sources

  • Check Point CheckMates – Check Point’s official announcement confirms CVE-2026-91843, CVSS 9.8, the possibility of unauthenticated remote code execution as root, and LivePatch availability.
  • NHS England Digital – Independently confirms the nature of the flaw, the affected server types, the recommendation to apply the fix, and the status of Smart-1 Cloud.
  • BleepingComputer – Corroborates that Check Point released security updates and describes the temporary restriction of access to trusted IP addresses.

Verified and updated: 09/18/2026 15:23

Sharing