· via dev.to (home feed)
Unauthenticated stack overflow in Check Point management servers enables root code execution
A pre-authentication stack overflow in Check Point management and log servers lets remote attackers run code as root without credentials. Fixes are available under vendor advisory sk1000155.

What happened
A critical remote code execution vulnerability, tracked as CVE-2026-91843, has been disclosed in several Check Point management products. According to a technical write-up on dev.to, the flaw affects the Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server. The post reports that India's CERT-In published the finding as vulnerability note CIVN-2026-0465 on 18 September 2026 and assigned it a critical rating.
How the flaw works
The defect is a stack buffer overflow that sits on the unauthenticated login path. A remote attacker submits a maliciously constructed request to the login handler; the malformed input overruns a stack buffer and gives the attacker the ability to redirect program execution. Because the vulnerable code runs before any credentials are checked, no valid username or password is needed, and no prior foothold on the network is required beyond the ability to reach the management interface. According to the dev.to write-up, successful exploitation results in arbitrary code execution with root privileges on the targeted server.
What an attacker gains
A management or log server is a high-value target within a security deployment. These systems hold the security policies, gateway configurations and log data for the environments they administer. With root access, the write-up warns, an attacker could rewrite policy, disable enforcement, read or tamper with stored logs, and use the compromised server as a stepping stone toward the gateways it manages.
Affected versions
The dev.to post lists the following releases as affected:
- R82.20
- R82.10 up to and including Jumbo Hotfix Take 44
- R82 up to and including Jumbo Hotfix Take 126
- R81.20 up to and including Jumbo Hotfix Take 166
- R81.10 up to and including Jumbo Hotfix Take 190, which is end of support
- R80, R80.10, R80.20, R80.30, R80.40 and R81, all of which are end of support
Remediation and mitigation
Organizations should apply the vendor fixes described in Check Point advisory sk1000155 and referenced in the CERT-In note. Where an affected build cannot be patched right away, the write-up recommends limiting access to management and log server interfaces so that only trusted administrative networks can reach them, and watching for anomalous login attempts against those services. Deployments still running end-of-support releases cannot count on new hotfixes and should be moved to a supported version train.
Why it matters
Pre-authentication remote code execution on a security management server is close to a worst-case scenario for a network security team. The management plane is the source of truth for firewall policy; an attacker with root there can rewrite rules, weaken enforcement and tamper with the very logs that would reveal the intrusion, all while holding a trusted channel to the managed gateways. Because exploitation requires nothing more than reachability to the management interface, exposure often comes down to network architecture: management ports visible to broad or untrusted networks convert a server-side bug into full infrastructure compromise. The disclosure also illustrates the practical cost of running end-of-support software — several affected trains will not receive fixes at all, leaving upgrades as the only genuine remediation path.
It is worth noting that this report currently rests on a single published write-up summarizing the CERT-In note and the Check Point advisory. Teams running affected Check Point deployments should verify version and hotfix details directly against the vendor's guidance before planning their patch window.
- #check-point
- #vulnerability
- #remote-code-execution
- #security
- #patch-management