Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root Swati KhandelwalSep 17, 2026Vulnerability / Enterprise Security A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw has been exploited.Check Point told The Hacker News that the vulnerable path runs only through the Trusted Clients setting, which controls which hosts may connect to the management server through SmartConsole. The flaw, tracked as CVE-2026-91843 and rated…
CVEs: CVE-2026-91843, CVE-2026-16232, CVE-2026-62144, CVE-2026-18574, CVE-2026-85103
Original source: thehackernews.com