T

Threats

Check Point Management Authentication Bypass

Overview

  • CVE: CVE-2026-18574

  • Severity: Critical

  • CVSS: 9.3

  • Advisory date: 3 August 2026

  • Products: Check Point Security Management Server and Multi-Domain Security Management Server (MDS)

  • Exploitation status: Check Point reports no indication of active exploitation.


Affected Versions

Check Point Security Management Server and Multi-Domain Security Management Server

  • Affected: R80, R80.10, R80.20, R80.30, R80.40, R81 and R81.10, all of which are end of support. Also affected are R81.20 Jumbo Hotfix Accumulator Take 160 or earlier, R82 Take 121 or earlier, and R82.10 Take 39 or earlier.

  • Fixed: R81.20 Jumbo Hotfix Accumulator Take 161 or later, R82 Take 122 or later, and R82.10 Take 40 or later. End-of-support releases must be upgraded to a supported branch and the applicable fixed take installed.

  • Not affected: Smart-1 Cloud customers are already protected.

  • Source: Check Point sk185222 - CVE-2026-18574 Management Authentication Bypass


Vulnerability Breakdown

CVE-2026-18574 - Management Authentication Bypass

  • Severity: Critical

  • CVSS: 9.3

  • Description: An authentication bypass may allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on a Security Management Server.

  • Impact: Successful exploitation could fully compromise the Security Management system.

  • Conditions: The attacker requires network access to the Security Management Server. Exposure is higher when Management services are reachable from untrusted networks or Trusted Clients are not restricted.

  • Exploitation status: Check Point discovered the issue internally and reports no indication of active exploitation.


Mitigation

  • Install the applicable fixed Jumbo Hotfix Accumulator take on every affected Security Management Server and MDS deployment.

  • Upgrade end-of-support R80 through R81.10 deployments to a supported branch, then install the applicable fixed take.

  • Restrict Trusted Clients to authorised administrative hosts.

  • Limit Management services to trusted administrative networks and prevent direct exposure to untrusted networks.

  • Confirm the installed take after deployment and review Management access controls.


Summary for IT Teams

  • Products: Check Point Security Management Server and Multi-Domain Security Management Server

  • Threat Level: Critical, CVSS 9.3

  • Action Required: Apply R81.20 Take 161, R82 Take 122, R82.10 Take 40, or a later applicable take. Upgrade end-of-support branches and restrict Management access to trusted administrative hosts and networks.


Reference


Need Help?

Secure ISS can help your organisation identify affected Check Point deployments, validate Management exposure and prioritise remediation. Contact the Secure ISS team on 1300 769 460.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.