What Happened
Check Point disclosed CVE-2026-91843, a critical vulnerability affecting Security Management and Log Server products, letting an unauthenticated attacker remotely execute arbitrary code with root privileges through the login process. The company says it has found no evidence of in-the-wild exploitation, but has shared indicators of compromise with customers as a precaution. Check Point advises administrators who have not enabled automatic updates to patch their installations immediately. The disclosure came the same week Tanium and Kaspersky each shipped their own fixes for high- and medium-severity flaws in their security products, part of a pattern of threat actors setting their sights on the vendors organizations rely on to defend their networks. Read the advisory from SecurityWeek.
Why This Matters for Canadian Organizations
Check Point Security Management servers sit at the center of network defense for many Canadian banks, insurers, and government agencies, controlling firewall policy, logging, and access across an entire security estate. A root-level compromise of the management layer hands an attacker the ability to rewrite security policy, disable logging, and move freely across connected systems, undermining every downstream control the organization depends on. Financial institutions operating under OSFI Guideline B-13 and organizations subject to PIPEDA breach-notification obligations face direct exposure if these deployments go unpatched, since a compromised management server erases the audit trail regulators expect to see after an incident.
What to Do
Security teams running Check Point Security Management or Log Server products should apply the vendor’s patch without delay, particularly where automatic updates remain disabled. Administrators should review the indicators of compromise Check Point published and check login and administrative logs for unexplained activity predating the patch. Teams managing Tanium or Kaspersky products in the same environment should confirm this week’s advisories are applied as well, since a gap in any one management layer weakens the rest.






