Security Management and SmartConsole

CVE-2026-18574: Authentication Bypass in Check Point Security Management Server

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server.

Published

ExploitedNot in CISA KEV
Ransomware useNot reportedPer CISA
SeverityCRITICALCVSS 4.0 9.3
EPSS0.89%Chance of exploitation in 30 days
Public exploitNot tracked
FixNot yet

Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.

Affected and fixed versions

Product / branchFixed in
Security Management Server R82.10 with Jumbo Hotfix Accumulator Take 39 or belowSee the advisory
Security Management Server R82 with Jumbo Hotfix Accumulator Take 121 or belowSee the advisory
Security Management Server R81.20 with Jumbo Hotfix Accumulator Take 160 or belowSee the advisory
Security Management Server R81.10See the advisory
Security Management Server R81See the advisory
Security Management Server R80.40See the advisory
Security Management Server R80.30See the advisory
Security Management Server R80.20See the advisory
Security Management Server R80.10See the advisory
Security Management Server R80See the advisory
Multi-Domain Security Management Server R82.10 with Jumbo Hotfix Accumulator Take 39 or belowSee the advisory
Multi-Domain Security Management Server R82 with Jumbo Hotfix Accumulator Take 121 or belowSee the advisory
Multi-Domain Security Management Server R81.20 with Jumbo Hotfix Accumulator Take 160 or belowSee the advisory
Multi-Domain Security Management Server R81.10See the advisory
Multi-Domain Security Management Server R81See the advisory
Multi-Domain Security Management Server R80.40See the advisory
Multi-Domain Security Management Server R80.30See the advisory
Multi-Domain Security Management Server R80.20See the advisory
Multi-Domain Security Management Server R80.10See the advisory
Multi-Domain Security Management Server R80See the advisory

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.

Sources

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.