Check Point Security Management Server Auth Bypass Enables Remote Command Exec
CVE-2026-18574 Published on August 3, 2026
Authentication Bypass in Check Point Security Management Server
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.
Vulnerability Analysis
CVE-2026-18574 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
Authentication Bypass Using an Alternate Path or Channel
A product requires authentication, but the product has an alternate path or channel that does not require authentication.
Affected Versions
checkpoint Security Management Server:- Version R82.10 with Jumbo Hotfix Accumulator Take 39 or below is affected.
- Version R82 with Jumbo Hotfix Accumulator Take 121 or below is affected.
- Version R81.20 with Jumbo Hotfix Accumulator Take 160 or below is affected.
- Version R81.10 is affected.
- Version R81 is affected.
- Version R80.40 is affected.
- Version R80.30 is affected.
- Version R80.20 is affected.
- Version R80.10 is affected.
- Version R80 is affected.
- Version R82.10 with Jumbo Hotfix Accumulator Take 39 or below is affected.
- Version R82 with Jumbo Hotfix Accumulator Take 121 or below is affected.
- Version R81.20 with Jumbo Hotfix Accumulator Take 160 or below is affected.
- Version R81.10 is affected.
- Version R81 is affected.
- Version R80.40 is affected.
- Version R80.30 is affected.
- Version R80.20 is affected.
- Version R80.10 is affected.
- Version R80 is affected.