T
Threats
Check Point Quantum Security Management Critical Vulnerability
Overview
CVE: CVE-2026-62144
Severity: Critical
Date: 24 July 2026
Excerpt
Check Point has disclosed a critical authentication bypass vulnerability affecting Quantum Security Management and Multi-Domain Security Management. The flaw allows unauthenticated remote attackers to run administrative commands on the Management Server, with the potential to reach connected Security Gateways. Organisations without firewall protection or Trusted Client restrictions on their Management Server face the highest risk.
Affected Versions
The vulnerability affects Check Point Security Management and Multi-Domain Security Management Server (MDS) across the following releases:
R82.10 — fixed in Jumbo Hotfix Accumulator Take 36 or later
R82 — fixed in Jumbo Hotfix Accumulator Take 118 or later
R81.20 — fixed in Jumbo Hotfix Accumulator Take 158 or later
R81.10 (EOS), R81 (EOS), R80.40 (EOS), R80.30 (EOS), R80.20 (EOS), R80.10 (EOS), R80 (EOS), and R77.30 (EOS) — affected; organisations running an end-of-support release should upgrade to a supported version and apply the latest Jumbo Hotfix.
Exposure is highest where the Management Server is reachable without firewall protection or where Trusted Clients (GUI clients) are unrestricted. Check Point recommends allowing only trusted IP addresses or subnets and not using Any as the Trusted Client type.
Vulnerability Breakdown
CVE-2026-62144 - Authentication Bypass
Severity: Critical
CVSS: 9.1
Description: An authentication bypass in Check Point Security Management and Multi-Domain Security Management lets an unauthenticated remote attacker execute administrative commands on the Management Server.
Impact: Successful exploitation may also allow command execution on managed Security Gateways, risking full network compromise.
Conditions: Exploitation requires network access to the Management Server that is not protected by a firewall, or a configuration that does not restrict Trusted Clients.
Notes: Risk is significantly reduced where Trusted Client restrictions and firewall protections are correctly enforced.
Mitigation
Apply the latest Check Point patch for Quantum Security Management immediately.
Restrict network access to the Management Server using a firewall.
Configure and enforce Trusted Client restrictions on the Management Server.
Review Management Server logs for unauthorised administrative activity.
Summary for IT Teams
Products: Check Point Quantum Security Management, Multi-Domain Security Management
Threat Level: Critical, CVSS 9.1
Action Required: Patch the Management Server immediately, restrict network access, and enforce Trusted Client controls.
Reference
Need Help?
Secure ISS clients requiring assistance assessing exposure or applying vendor patches can contact our SOC team on 1300 769 460 or via email.

