
[CIVN-2026-0465] Remote Code Execution Vulnerability in Check Point Security Management and Log Servers
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Remote Code Execution Vulnerability in Check Point Security Management and Log Servers
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server versions
R82.20
R82.10 Jumbo Hotfix Take 44 or prior
R82 Jumbo Hotfix Take 126 or prior
R81.20 Jumbo Hotfix Take 166 or prior
R81.10 Jumbo Hotfix Take 190 or prior (End of support)
R80, R80.10, R80.20, R80.30, R80.40, R81 (all of which are end of support)
Overview
A vulnerability has been reported in Check Point Security Management and Log Servers that could allow a remote attacker to execute arbitrary code and elevate privileges on the targeted system.
Target Audience:
All organizations and individuals using the affected Check Point products.
Risk Assessment:
High risk of remote code execution and privilege escalation.
Impact Assessment:
Potential for execute arbitrary code and elevate privileges on the targeted system.
Description
Check Point Security Management and Log Servers are centralized components of Check Point security infrastructure used to manage security policies, configure security gateways, and collect/store security logs and events.
This vulnerability exists in Check Point Security Management and Log Servers due to a stack overflow in the unauthenticated login process. A remote attacker could exploit this vulnerability by sending a specially crafted request to the targeted system during the login process.
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code with root privileges.
Solution
Apply appropriate security updates as mentioned by the vendor:
https://support.checkpoint.com/results/sk/sk1000155
Vendor Information
Check Point
https://support.checkpoint.com/results/sk/sk1000155
References
https://support.checkpoint.com/results/sk/sk1000155
CVE Name
CVE-2026-91843
– – —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
– –
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqtVCgACgkQ3jCgcSdc
ys+FPw//Q//faIZkbh1WvKleTABkL85mh83Snvq7wvnM6L5y2C0mAWo9AZOVgq7+
tlXIYa/NK90hp8Te+Nikg3NrtRsbPiVBZLFhzrtbgbKfYa168iBtm8X0yCBI58Vx
royXqg7BQIZn8alu8J9O1ZWXlyKTDvc6rb6uZIEffIKdZSPo8xn5vL0ZE/v/QS4E
m+243KLMv0Cj9jFsz1/Yy81m0HJCNF6QxVSubX+TbTh06DTBVv0tUNQ9Vj23hPQ3
ty3Lot0zw0iB9FKyQ+PgJkh2cGiP5bOAw5mP3/kZc9E2PviegozCY5qD9VPWH6xr
qB5rvIrm4FgQOP57+UDDbeatev3l81u4jz7wH7i3LMvdn2HYyzF8Ak1/Sl88bjZ4
v4sDbcHNcfEReRohtC8ma+hSy9BUY5YrwkNcfuuOaD/eZKtzyMAmJdhRT3+ZfLQW
ChLhLYzSn2Mq05vRBlNcyrML2582IFqp/CdpiMVbw+GqU1KPKWIQYWZWPZ3k+uB/
JUHv4UWQpLAyHbEffHOuMmamrkcAQ11KYBPUl2psL6iQq0TrB0oUB3wz2Ea/KNUy
EEGxpXzz5AWCfXIitPTstAuU6xvADKvWt4CITf6Lr0SFBn96u7HSe1psAy/SAJG6
COs5+tYc5crn21crUuW9cyHPdAtfodQTHuwylrpgKlqTYa+ZJSE=
=jFVF
—–END PGP SIGNATURE—–


