T
Threats
Check Point Management Authentication Bypass
Overview
CVE: CVE-2026-18574
Severity: Critical
CVSS: 9.3
Advisory date: 3 August 2026
Products: Check Point Security Management Server and Multi-Domain Security Management Server (MDS)
Exploitation status: Check Point reports no indication of active exploitation.
Affected Versions
Check Point Security Management Server and Multi-Domain Security Management Server
Affected: R80, R80.10, R80.20, R80.30, R80.40, R81 and R81.10, all of which are end of support. Also affected are R81.20 Jumbo Hotfix Accumulator Take 160 or earlier, R82 Take 121 or earlier, and R82.10 Take 39 or earlier.
Fixed: R81.20 Jumbo Hotfix Accumulator Take 161 or later, R82 Take 122 or later, and R82.10 Take 40 or later. End-of-support releases must be upgraded to a supported branch and the applicable fixed take installed.
Not affected: Smart-1 Cloud customers are already protected.
Source: Check Point sk185222 - CVE-2026-18574 Management Authentication Bypass
Vulnerability Breakdown
CVE-2026-18574 - Management Authentication Bypass
Severity: Critical
CVSS: 9.3
Description: An authentication bypass may allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on a Security Management Server.
Impact: Successful exploitation could fully compromise the Security Management system.
Conditions: The attacker requires network access to the Security Management Server. Exposure is higher when Management services are reachable from untrusted networks or Trusted Clients are not restricted.
Exploitation status: Check Point discovered the issue internally and reports no indication of active exploitation.
Mitigation
Install the applicable fixed Jumbo Hotfix Accumulator take on every affected Security Management Server and MDS deployment.
Upgrade end-of-support R80 through R81.10 deployments to a supported branch, then install the applicable fixed take.
Restrict Trusted Clients to authorised administrative hosts.
Limit Management services to trusted administrative networks and prevent direct exposure to untrusted networks.
Confirm the installed take after deployment and review Management access controls.
Summary for IT Teams
Products: Check Point Security Management Server and Multi-Domain Security Management Server
Threat Level: Critical, CVSS 9.3
Action Required: Apply R81.20 Take 161, R82 Take 122, R82.10 Take 40, or a later applicable take. Upgrade end-of-support branches and restrict Management access to trusted administrative hosts and networks.
Reference
Need Help?
Secure ISS can help your organisation identify affected Check Point deployments, validate Management exposure and prioritise remediation. Contact the Secure ISS team on 1300 769 460.

