CVE-2026-91843: Unauthenticated Stack Overflow in Check Point Servers
CERT-In warned of a critical flaw, CVE-2026-91843, in Check Point Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server. A pre-authentication stack overflow in the login handler allows remote code execution with root privileges; fixes are in advisory sk1000155.
- Affected builds include R82.20, R82.10, R82, R81.20 and R81.10
- Exploitation needs no credentials and yields root-level code execution
- CERT-In rated the flaw CRITICAL on 18 September 2026
- Until patched, restrict management interfaces to trusted networks
Read next
Security