Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Malicious npm packages evade install-script defenses at runtime

    September 20, 2026

    Researchers escape OpenAI Codex sandbox to run commands on host

    September 20, 2026

    Microsoft Teams will let admins block custom file extensions

    September 20, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»New Check Point flaw lets hackers execute code with root privileges
    News

    New Check Point flaw lets hackers execute code with root privileges

    adminBy adminSeptember 18, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Check Point

    Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems.

    Tracked as CVE-2026-91843, this flaw stems from a stack-based buffer overflow weakness in the login process for Security Management Server instances, which manage Security Gateways (firewalls) and monitor network security events.

    The security issue also affects the company’s Log Server, a dedicated server that collects and stores logs generated by Check Point firewalls.

    Successful exploitation lets threat actors without privileges gain root remote code execution in low-complexity attacks that don’t require user interaction.

    Check Point also provided temporary mitigation measures for customers who can’t deploy the latest LivePatch, including hardening vulnerable systems against attacks and limiting access to trusted IP addresses/subnets by editing the entries under Manage & Settings > Permissions & Administrators > Trusted Clients in the SmartConsole dashboard.

    While the company has not yet flagged this security flaw as actively exploited, it said security teams can identify CVE-2026-91843 attacks by looking for “Administrator failed to log in: Username too long” alerts in the Audit and Admin login logs.

    CVE-2026-91843 alert SmartConsole
    CVE-2026-91843 alert in SmartConsole (Check Point Software)

    Last week, it patched another critical remote code execution flaw (CVE-2026-85103) stemming from a heap overflow in the VPN certificate ASN.1 decoding flow that affects Check Point firewalls and management systems.

    “All Security Management Server deployments are vulnerable, regardless of configuration,” Check Point warned. “The vulnerability is not dependent on any specific management configuration. The management is vulnerable even when VPN in not in use or configured.”

    The same day, it patched a second critical flaw (CVE-2026-85102) that lets unauthenticated hackers bypass authentication and execute code remotely on vulnerable firewalls.

    Although these vulnerabilities are not yet exploited in the wild, Check Point flagged other flaws as actively exploited in recent months.

    The first, an authentication bypass (CVE-2026-50751) zero-day, was abused by a Qilin ransomware affiliate since June, while a second authentication bypass zero-day (CVE-2026-16232) has been exploited since at least July to authenticate with administrator privileges to SmartConsole admin panels.

    More recently, the Dutch National Cyber Security Centre (NCSC-NL) warned organizations to prioritize patching two critical Check Point VPN flaws tracked as CVE-2026-85102 and CVE-2026-85103 because it “expects exploitation attempts to occur soon.”


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCyber Adversary Simulation (CyAS): scheme documents now available
    Next Article Contest to Open for Ed Sheeran Flooded With Free Palestine Videos and Fart Memes
    admin
    • Website

    Related Posts

    News

    Malicious npm packages evade install-script defenses at runtime

    September 20, 2026
    News

    Researchers escape OpenAI Codex sandbox to run commands on host

    September 20, 2026
    News

    Microsoft Teams will let admins block custom file extensions

    September 20, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Our Picks

    Malicious npm packages evade install-script defenses at runtime

    September 20, 2026

    Researchers escape OpenAI Codex sandbox to run commands on host

    September 20, 2026

    Microsoft Teams will let admins block custom file extensions

    September 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.