Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Berlin election campaign centers around radical-left drive to seize properties – POLITICO

    September 19, 2026

    Google’s Gemini AI hacked three companies in security test

    September 19, 2026

    Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

    September 19, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Berlin election campaign centers around radical-left drive to seize properties – POLITICO
    • Google’s Gemini AI hacked three companies in security test
    • Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
    • Bitcoin Blasts Past $80K and a Fresh Short Squeeze Is On
    • Scientists are about to test Einstein’s gravity with exotic matter
    • The Guardian view on NAZA’s persecuted directors: journalism is not treason | Editorial
    • UEFA, CONCACAF demand FIFA make $2.1 billion payout to member groups amid funding row
    • Gavin Newsom is pushing for an AI kill switch
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 19
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New Check Point flaw lets hackers execute code with root privileges

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 19, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems.

    Tracked as CVE-2026-91843, this flaw stems from a stack-based buffer overflow weakness in the login process for Security Management Server instances, which manage Security Gateways (firewalls) and monitor network security events.

    The security issue also affects the company’s Log Server, a dedicated server that collects and stores logs generated by Check Point firewalls.

    Successful exploitation lets threat actors without privileges gain root remote code execution in low-complexity attacks that don’t require user interaction.

    Check Point also provided temporary mitigation measures for customers who can’t deploy the latest LivePatch, including hardening vulnerable systems against attacks and limiting access to trusted IP addresses/subnets by editing the entries under Manage & Settings > Permissions & Administrators > Trusted Clients in the SmartConsole dashboard.

    While the company has not yet flagged this security flaw as actively exploited, it said security teams can identify CVE-2026-91843 attacks by looking for “Administrator failed to log in: Username too long” alerts in the Audit and Admin login logs.

    CVE-2026-91843 alert SmartConsole
    CVE-2026-91843 alert in SmartConsole (Check Point Software)

    Last week, it patched another critical remote code execution flaw (CVE-2026-85103) stemming from a heap overflow in the VPN certificate ASN.1 decoding flow that affects Check Point firewalls and management systems.

    “All Security Management Server deployments are vulnerable, regardless of configuration,” Check Point warned. “The vulnerability is not dependent on any specific management configuration. The management is vulnerable even when VPN in not in use or configured.”

    The same day, it patched a second critical flaw (CVE-2026-85102) that lets unauthenticated hackers bypass authentication and execute code remotely on vulnerable firewalls.

    Although these vulnerabilities are not yet exploited in the wild, Check Point flagged other flaws as actively exploited in recent months.

    The first, an authentication bypass (CVE-2026-50751) zero-day, was abused by a Qilin ransomware affiliate since June, while a second authentication bypass zero-day (CVE-2026-16232) has been exploited since at least July to authenticate with administrator privileges to SmartConsole admin panels.

    More recently, the Dutch National Cyber Security Centre (NCSC-NL) warned organizations to prioritize patching two critical Check Point VPN flaws tracked as CVE-2026-85102 and CVE-2026-85103 because it “expects exploitation attempts to occur soon.”


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    check Code Execute Flaw hackers lets Point privileges Root
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

    An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

    Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

    23 Million User Records Compromised in Gyazo Data Breach 

    Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts

    New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Berlin election campaign centers around radical-left drive to seize properties – POLITICO

    September 19, 2026

    Google’s Gemini AI hacked three companies in security test

    September 19, 2026

    Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

    September 19, 2026

    Bitcoin Blasts Past $80K and a Fresh Short Squeeze Is On

    September 19, 2026
    Latest Posts

    Texas deputy used 83K Flock cameras to find woman who had abortion. Was it a welfare check, as he claimed?

    August 4, 2026

    Trump’s Seabed Mining Order Is an Ecological and Political Disaster

    August 4, 2026

    ExxonMobil picks Sercel technology to support operations offshore Guyana

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Berlin election campaign centers around radical-left drive to seize properties – POLITICO

    September 19, 2026

    Google’s Gemini AI hacked three companies in security test

    September 19, 2026

    Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

    September 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.