New Check Point Flaw Lets Hackers Execute Code With Root Privileges
ID: 67b897af-a078-5cc4-9182-56fd6570bb3b
STIX ID: report--67b897af-a078-5cc4-9182-56fd6570bb3b
Feed Name: CosmicBytez Labs
**Check Point CVE-2026-91843 — critical unauthenticated RCE in Management and Log Servers:** Check Point patched a stack-based buffer overflow in the unauthenticated login process of Security Management Server and Log Server (including Multi-Domain variants) that allows remote code execution as root via an excessively long username (CVSS 9.8). The vendor distributes fixes via LivePatch (specific takes listed), recommends restricting SmartConsole access where LivePatch cannot be applied, and provides a log signature to detect exploitation attempts; no confirmed in-the-wild exploitation was reported at publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
