Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-91843

Stack overflow in login handler allows unauthenticated RCE as root

Stack overflow in Check Point Security Management Server login handler allows unauthenticated RCE as root. CVSS 9.8. Patch available via sk1000155.

cat cve-2026-91843.json
Vendor
Check Point
Product
Security Management Server, Log Server, Multi-Domain Server
CVSS
9.8
EPSS (exploit probability)
0.5%
Status
patched
Published

A stack overflow in the Check Point Security Management Server login process allows unauthenticated remote attackers to execute arbitrary code as root. The flaw requires no credentials and is reachable over the network.

Affected versions: R82.20 (all builds), R82.10 through Jumbo Hotfix Take 44, R82 through Take 126, R81.20 through Take 166, R81.10 through Take 190, and all end-of-support releases (R81, R80.40, R80.30, R80.20, R80.10, R80). Log Servers, Multi-Domain Servers, and standalone deployments are also affected.

Exploitation status: No active exploitation confirmed as of September 17, 2026. No public PoC. Not listed on the CISA Known Exploited Vulnerabilities catalog.

Patch: LivePatch via sk1000155. Systems with automatic updates enabled are already protected. End-of-support versions require a Check Point support ticket for a backport.

Structural note: Check Point’s advisory specifies the attack routes through the management API. The Trusted Clients setting limits which hosts can connect to that API.