# Check Point patches unauthenticated RCE flaw

Published: 2026-09-18 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/6b9fe205-bfac-5e6d-b71b-ad4c3df2dcd6/check-point-patches-unauthenticated-rce-flaw

> An unauthenticated stack-based buffer overflow in Check Point Security Management and Log Servers allows remote root code execution; patches are available.

NCSC-NL published an advisory regarding CVE-2026-91843, a stack-based buffer overflow vulnerability in Check Point's Security Management and Log Servers. The flaw occurs during the unauthenticated login process, meaning an attacker requires no prior credentials to exploit it. Successful exploitation allows an attacker to execute arbitrary code with root privileges, effectively bypassing authentication entirely and gaining full control over the affected system.

The vulnerability carries a CVSS v3 score of 9.8, reflecting its low attack complexity, lack of authentication requirements, and high impact on confidentiality, integrity, and availability. Check Point has released updates to address the issue. Defenders running Check Point Security Management or Log Servers should prioritize applying the vendor's patches immediately given the severity and remote unauthenticated nature of the flaw. No information was provided in this advisory regarding active exploitation in the wild.

## Mentioned in this report

- Vulnerabilities: CVE-2026-91843

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0384.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/6b9fe205-bfac-5e6d-b71b-ad4c3df2dcd6/check-point-patches-unauthenticated-rce-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
