DEV Community

CVE Reports
CVE Reports

Posted on • Originally published at cvereports.com

CVE-2026-18574: CVE-2026-18574: Authentication Bypass via Alternate Path in Check Point Security Management Server

CVE-2026-18574: Authentication Bypass via Alternate Path in Check Point Security Management Server

Vulnerability ID: CVE-2026-18574
CVSS Score: 9.3
Published: 2026-08-03

A critical authentication bypass vulnerability (CVE-2026-18574) in Check Point Security Management and Multi-Domain Security Management (MDS) Servers allows unauthenticated remote attackers to execute arbitrary system commands with administrative privileges. The flaw stems from an alternate path authentication bypass (CWE-288) in the management interface daemons.

TL;DR

Unauthenticated remote command execution on Check Point Security Management Servers via alternate path authentication bypass (CWE-288), CVSS 9.3.


Technical Details

  • CWE ID: CWE-288
  • Attack Vector: Network
  • CVSS: 9.3
  • EPSS: Not assigned
  • Impact: Arbitrary Command Execution / Full Compromise
  • Exploit Status: None
  • KEV Status: Not Listed

Affected Systems

  • Check Point Security Management Server
  • Check Point Multi-Domain Security Management Server (MDS)
  • Check Point Security Management Server / MDS: R81.20 (Fixed in: R81.20 Jumbo HFA Take 161)
  • Check Point Security Management Server / MDS: R82 (Fixed in: R82 Jumbo HFA Take 122)
  • Check Point Security Management Server / MDS: R82.10 (Fixed in: R82.10 Jumbo HFA Take 40)

Mitigation Strategies

  • Apply Jumbo Hotfix Accumulator updates for R81.20, R82, or R82.10 immediately.
  • Restrict administrative GUI clients (Trusted Clients) in SmartConsole to authorized IPs.
  • Isolate administrative ports (TCP 18190, 443, 19009) from untrusted networks and the public internet.

Remediation Steps:

  1. Identify current software version and Jumbo Hotfix Take running on the Security Management Server or Multi-Domain Server.
  2. For R82.10, install Jumbo Hotfix Accumulator starting from Take 40.
  3. For R82, install Jumbo Hotfix Accumulator starting from Take 122.
  4. For R81.20, install Jumbo Hotfix Accumulator starting from Take 161.
  5. For legacy versions (R81.10, R81, R80.x), upgrade to a supported release first.
  6. Open SmartConsole, navigate to Manage & Settings > Permissions & Administrators > Trusted Clients, and restrict access to authorized administration hosts.
  7. Apply firewall rules to enforce network-level restrictions on administrative ports.

References


Read the full report for CVE-2026-18574 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)