Critical Check Point flaw lets unauthenticated attackers gain root via stack overflow
A critical pre-authentication vulnerability, CVE-2026-91843, has been discovered in Check Point Security Management and Log Servers, allowing unauthenticated attackers to execute arbitrary code as root. The flaw exists in the login process, meaning no credentials are required for an attacker to exploit it by sending a crafted network request that triggers a stack overflow. CERT-In has catalogued the issue as CIVN-2026-0465 with a critical severity rating. Affected products span multiple versions including R82.20, R82.10, R81.20, R81.10, and several end-of-support R80/R81 release trains. Check Point has released patches via advisory sk1000155, and administrators are advised to apply updates immediately while restricting network access to management interfaces in the interim.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in