Summary
- CVE-2026-91843 affects Check Point Security Management, Multi-Domain Management, and Log Server products.
- The vulnerability can permit unauthenticated remote code execution as root and carries a CVSS score of 9.8.
- Check Point says it has no indication that the vulnerability has been exploited in the wild.
Check Point has released a security fix for a critical vulnerability that can allow an unauthenticated remote attacker to execute arbitrary code with root privileges on security-management and logging systems.
CVE-2026-91843 is a stack-based buffer overflow in the unauthenticated login process and carries a CVSS score of 9.8.
The flaw affects Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server across several software branches. NHS England issued a UK cyber alert on 17 September after Check Point published its update.
Check Point says it has no indication that the vulnerability has been exploited in the wild at the time of disclosure. The absence of confirmed exploitation distinguishes it from several other serious security-product vulnerabilities disclosed during September, while the technical impact remains substantial.
The vendor is distributing protection through LivePatch and says customers with automatic updates enabled are already protected. Smart-1 Cloud is listed as unaffected because the remediation has already been implemented in that environment.
The location of the flaw increases its potential consequence. Security-management servers sit above individual gateways and can hold firewall policy, administrator configuration, logging information, trust relationships, and other data used to operate security controls across an organisation.
Root access to that layer does not automatically establish compromise of every device it manages, but it can place an attacker inside a highly trusted administrative system with visibility into the wider security environment.
Centralisation creates that trade-off deliberately. A common management plane improves consistency, auditability, policy deployment, and administrative efficiency. It also creates a control point whose compromise can have wider significance than compromise of an ordinary application server.
Log servers create a related evidential concern. Security records are used for detection, investigation, reconstruction of incidents, and sometimes regulatory evidence. If a system storing or processing those records is itself compromised with root privileges, investigators need to consider whether locally held information remains complete and trustworthy.
The vulnerability is reachable before authentication. That removes the need for an attacker to obtain administrator credentials before reaching the vulnerable login process, although actual exposure will still depend on network architecture and how management interfaces are restricted.
Check Point’s hardening guidance recommends limiting management access to known internal addresses rather than exposing administrative systems broadly. That architectural control remains relevant even after patches are applied because the management plane continues to hold privileged access to the wider environment.
The disclosure follows several other high-severity vulnerabilities affecting security infrastructure this year. Firewalls, VPN gateways, identity appliances, security-management platforms, and email-security systems are attractive targets partly because they sit at trusted boundaries and frequently have elevated access to other systems.
That means vulnerability severity cannot be assessed only through the CVSS number. Where the affected asset controls policy, authentication, or security evidence for other devices, compromise can have a disproportionate operational effect.
NHS England has directed affected organisations to the Check Point advisory for definitive remediation guidance. With no confirmed exploitation at disclosure, the immediate question is exposure and patch state rather than incident attribution, but an unauthenticated root-level flaw in security-management infrastructure leaves little room for delay where vulnerable systems are reachable.




