www.securityweek.com 18 Sept 2026, 07:14 UTC

Check Point Fixes Critical Flaw Allowing Root-Level Remote Code Execution

Check Point Fixes Critical Flaw Allowing Root-Level Remote Code Execution
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

CHECK Point, Kaspersky and Tanium have patched serious vulnerabilities in their security products, including flaws that could enable remote code execution. Check Point’s critical vulnerability, CVE-2026-91843, affects its Security Management and Log Server products. An unauthenticated attacker could exploit the login process to execute arbitrary code with root privileges.

Check Point said there is no evidence that this vulnerability has been exploited in the wild, although it has provided potential indicators of compromise. Customers without automatic updates enabled have been advised to install the security update immediately.

Tanium issued five advisories covering high- and medium-severity issues. Tanium Asset received fixes for two high-severity SQL injection vulnerabilities that authenticated attackers could use to read or alter restricted data, or tamper with SQL queries run by the service. Threat Response was also patched against SQL query tampering, server-side request forgery that could expose restricted data, and an improper access-control flaw that could allow attackers to create or modify alerts.

Separately, Kaspersky said on 17 September that Kaspersky Security 10 for Linux Mail Server is affected by a Redis vulnerability discovered in 2023. The company said the issue could potentially cause product malfunction or allow code execution when processing files in a particular format.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline