criticalZero-Day

Critical Unauthenticated RCE in Check Point Security Management and Log Servers

First seen Sep 18, 2026 · Updated Sep 18, 2026 · CVSS 9.8

check-pointunauthenticated-rceroot-accessnetwork-securityfirewall-managementpatch-availableagent-relevant

A critical unauthenticated remote code execution vulnerability has been disclosed in Check Point's Security Management and Log Servers, allowing attackers to gain root-level access over the network without credentials. Check Point has released a LivePatch fix and reports no evidence of active exploitation, but the flaw poses severe risk given the central role these servers play in firewall policy and administrator access control.

Technical Analysis

The vulnerability resides in Check Point's Security Management Server, the system responsible for centralized firewall policy enforcement and administrator authentication, and affects associated Log Servers. Exploitation allows an unauthenticated network attacker to execute arbitrary code with root privileges, indicating a likely input validation, authentication bypass, or memory corruption flaw in a network-facing management service. No CVE identifier was provided in the source reporting. Given the server's role in controlling firewall policy and admin credentials, a successful compromise could enable full network perimeter takeover, policy manipulation, and lateral movement into internal infrastructure. Organizations running AI agents or automated tooling behind Check Point-managed perimeters face elevated risk, as a root compromise of the management server could allow attackers to alter firewall rules protecting agent orchestration hosts, RAG pipelines, or API gateways, exposing credentials and internal endpoints those agents rely on.

Affected Systems

Check Point Security Management Servers and Log Servers (specific version ranges not disclosed in source reporting); environments where these servers are exposed to network access without additional segmentation

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) disclosed in source reporting at time of publication

Remediation Steps

  1. 1

    Apply LivePatch Immediately

    Deploy the LivePatch update released by Check Point for Security Management and Log Servers as soon as possible without waiting for a maintenance window.

  2. 2

    Restrict Network Exposure

    Limit network access to Security Management Server interfaces to trusted internal IP ranges only, and ensure management interfaces are not exposed to the public internet.

  3. 3

    Monitor for Exploitation Indicators

    Review logs on management and log servers for unusual root-level process execution, unexpected policy changes, or anomalous administrative logins.

  4. 4

    Validate Patch Application

    Confirm LivePatch was successfully applied across all management and log server instances, including any clustered or high-availability deployments.

  5. 5

    Audit Downstream Trust Relationships

    Review firewall policies and credentials managed through the affected servers, including any that gate access to AI agent infrastructure, API keys, or internal automation systems, for signs of tampering.

Industries Most Exposed

all industries using Check Point network security infrastructurefinancial serviceshealthcaregovernmenttechnologytelecommunications

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.