Critical Check Point Vulnerability (CVE-2026-91843)

Check Point has issued a warning about a new critical vulnerability CVE-2026-91843 (CVSS 9.8), affecting the Multi-Domain Security Management Server and Security Management Server products. The vulnerability allows an unauthenticated attacker to remotely execute arbitrary code on the device with root user privileges. Security updates are required, and it is essential to ensure the system is updated to at least one of the specified versions: If using Check Point LivePatch automatic update service, verify that updates have been successfully applied and the patch is installed using the command cplp list. A successful update will display the patch with the comment CVE-2026-91843. If updates cannot be performed, restrict the Web interface to trusted clients only using the Trusted Clients functionality (Manage & Settings > Permissions & Administrators > Trusted Clients). The vulnerability affects the following versions of Multi-Domain Security Management Server and Security Management Server: For more information: https://support.checkpoint.com/results/sk/sk1000155

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source