T

Threats

Check Point Quantum Security Management Critical Vulnerability

Overview

  • CVE: CVE-2026-62144

  • Severity: Critical

  • Date: 24 July 2026


Excerpt

Check Point has disclosed a critical authentication bypass vulnerability affecting Quantum Security Management and Multi-Domain Security Management. The flaw allows unauthenticated remote attackers to run administrative commands on the Management Server, with the potential to reach connected Security Gateways. Organisations without firewall protection or Trusted Client restrictions on their Management Server face the highest risk.


Affected Versions

The vulnerability affects Check Point Security Management and Multi-Domain Security Management Server (MDS) across the following releases:

  • R82.10 — fixed in Jumbo Hotfix Accumulator Take 36 or later

  • R82 — fixed in Jumbo Hotfix Accumulator Take 118 or later

  • R81.20 — fixed in Jumbo Hotfix Accumulator Take 158 or later

  • R81.10 (EOS), R81 (EOS), R80.40 (EOS), R80.30 (EOS), R80.20 (EOS), R80.10 (EOS), R80 (EOS), and R77.30 (EOS) — affected; organisations running an end-of-support release should upgrade to a supported version and apply the latest Jumbo Hotfix.

Exposure is highest where the Management Server is reachable without firewall protection or where Trusted Clients (GUI clients) are unrestricted. Check Point recommends allowing only trusted IP addresses or subnets and not using Any as the Trusted Client type.


Vulnerability Breakdown

CVE-2026-62144 - Authentication Bypass

  • Severity: Critical

  • CVSS: 9.1

  • Description: An authentication bypass in Check Point Security Management and Multi-Domain Security Management lets an unauthenticated remote attacker execute administrative commands on the Management Server.

  • Impact: Successful exploitation may also allow command execution on managed Security Gateways, risking full network compromise.

  • Conditions: Exploitation requires network access to the Management Server that is not protected by a firewall, or a configuration that does not restrict Trusted Clients.

  • Notes: Risk is significantly reduced where Trusted Client restrictions and firewall protections are correctly enforced.


Mitigation

  • Apply the latest Check Point patch for Quantum Security Management immediately.

  • Restrict network access to the Management Server using a firewall.

  • Configure and enforce Trusted Client restrictions on the Management Server.

  • Review Management Server logs for unauthorised administrative activity.


Summary for IT Teams

  • Products: Check Point Quantum Security Management, Multi-Domain Security Management

  • Threat Level: Critical, CVSS 9.1

  • Action Required: Patch the Management Server immediately, restrict network access, and enforce Trusted Client controls.


Reference


Need Help?

Secure ISS clients requiring assistance assessing exposure or applying vendor patches can contact our SOC team on 1300 769 460 or via email.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.