Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
Check Point vulnerability allows unauthenticated attackers to run code as root on Security Management and Log Servers. Fix available through LivePatch.
Intelligence analysis by Qwen 2.5 (3B)

Check Point has patched a critical vulnerability in its Security Management and Log Servers, which could allow attackers to run code as root without authentication.
Check Point found a bug in their security system that lets bad guys run programs as if they were the boss of the computer without needing a password. They fixed it with a special update.
Analysis
{"# Trusted Clients Setting":"The flaw is triggered by the Trusted Clients setting, which controls which hosts may connect to the management server through SmartConsole. Check Point recommends verifying that the setting is not set to any IP address but to trusted hosts.","# LivePatch Update Channel":"Check Point has released a fix through its LivePatch update channel, which is available for customers with automatic updates enabled. For those without automatic updates, the fix can be applied manually.","# CVE-2026-91843":"The vulnerability is tracked as CVE-2026-91843 and rated 9.8 out of 10 on the CVSS scale. It affects Check Point's R81.10 and older branches, as well as standalone deployments and Log Servers and Multi-Domain servers."}
Key points
- Check Point patched a critical vulnerability in its Security Management and Log Servers
- The flaw allows unauthenticated attackers to run code as root
- The fix is available through the LivePatch update channel
- The vulnerability affects Check Point's R81.10 and older branches
The fix should prevent attackers from exploiting this vulnerability, securing Check Point's systems and protecting against potential attacks.
If the fix is not applied, attackers could still exploit this vulnerability, potentially leading to unauthorized code execution and security breaches.



