Critical Check Point Vulnerability Allows Hackers to Execute Code as Root

www.news4hackers.com-critical-check-point-vulnerability-allows-hackers-to-execute-code-as-root-critical-check-point-vulnerability-allows-hackers-to-execute-code-as-root

New Check Point Software has issued security patches to resolve a critical vulnerability that could allow attackers to execute code with elevated privileges on management systems.

Critical Vulnerability Details

Identified as CVE-2026-91843, this flaw arises from a stack-based buffer overflow in the login process for Security Management Server environments, which oversee Security Gateways (firewalls) and monitor network security infrastructure. The vulnerability also impacts the company’s Log Server, which aggregates and stores logs generated by Check Point firewalls.

Exploitation and Risks

Exploitation of this flaw enables threat actors to achieve remote code execution with root privileges through low-complexity attacks that do not require user interaction. Check Point has outlined temporary mitigation strategies for organizations unable to apply the latest LivePatch update, including system hardening measures and restricting access to trusted IP addresses or subnets via the SmartConsole dashboard under Manage & Settings > Permissions & Administrators > Trusted Clients.

Recent Security Fixes and Threat Landscape

This follows recent fixes for two other critical remote code execution flaws affecting Check Point systems. The first, CVE-2026-85103, involved a heap overflow in the VPN certificate ASN.1 decoding process, impacting firewalls and management systems. Check Point emphasized that all Security Management Server deployments are inherently vulnerable regardless of configuration, as the flaw is independent of specific management settings or VPN usage.

Additional Vulnerabilities

A separate critical vulnerability, CVE-2026-85102, allows unauthenticated attackers to bypass authentication mechanisms and execute code remotely on affected firewalls. While these specific issues remain unreported as actively exploited, Check Point has noted ongoing threats related to other vulnerabilities. A zero-day authentication bypass flaw (CVE-2026-50751) has been linked to Qilin ransomware activities since June, and another authentication bypass vulnerability (CVE-2026-16232) has been used since July to gain administrative access to SmartConsole panels.

Security Recommendations

The Dutch National Cyber Security Centre (NCSC-NL) recently advised organizations to prioritize patching CVE-2026-85102 and CVE-2026-85103 due to anticipated exploitation attempts. Buffer overflow vulnerabilities in Check Point Software have led to remote code execution capabilities with root-level access. The flaw affects Security Management Servers and Log Servers, enabling attackers to execute arbitrary code without user interaction.

Patch and Mitigation Strategies

Check Point recommends applying security patches and implementing network restrictions as immediate countermeasures. Recent security updates address multiple critical vulnerabilities, including those impacting VPN certificate processing and authentication mechanisms. Organizations are urged to monitor system logs for specific alert patterns indicative of exploitation attempts. Security advisories highlight the importance of timely patch management to mitigate risks associated with active threat actor campaigns.



About Author

en_USEnglish