Critical Remote Code Execution (CVE‑2026‑91843) in Check Point Security Management & Log Servers
What It Is – Check Point disclosed CVE‑2026‑91843, a stack‑overflow flaw in the login routine of its Security Management and Log Server appliances. The defect allows an unauthenticated network attacker to execute arbitrary code with root privileges.
Exploitability – CVSS 9.8 (Critical). No public proof‑of‑concept or wild‑use has been observed, but the attack requires only a crafted login request with an oversized username.
Affected Products – Check Point Security Management and Log Server versions: R82.20; R82.10 Jumbo Hotfix ≤ 44; R82 Jumbo Hotfix ≤ 126; R81.20 Jumbo Hotfix ≤ 166; R81.10 Jumbo Hotfix ≤ 190 (EoS); all R80‑R81 EoS releases.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous control monitoring: a single code‑execution gap can invalidate the “secure configuration” control across multiple frameworks.
- Provides evidence that patch‑management processes must be auditable and demonstrable in real time.
- Highlights the importance of restricting privileged network access (Trusted Clients) as a control that can be verified in a Trust Center audit.
Recommended Actions
- Verify patch status via Check Point LivePatch; apply sk1000155 immediately on any unpatched appliance.
- Enable automatic updates to ensure future critical fixes are applied without delay.
- Limit Trusted Clients access to known internal IP ranges and document the restriction as part of your access‑control evidence.
- Follow the Check Point Management and Gateway hardening guide and capture the configuration as compliance evidence.
- Monitor network traffic for anomalous login requests and log any detection in your SIEM for audit trails.
Source: Security Affairs – Check Point Fixes Critical CVE‑2026‑91843