CVE-2026-18574: Authentication Bypass via Alternate Path in Check Point Security Management Server
Vulnerability ID: CVE-2026-18574
CVSS Score: 9.3
Published: 2026-08-03
A critical authentication bypass vulnerability (CVE-2026-18574) in Check Point Security Management and Multi-Domain Security Management (MDS) Servers allows unauthenticated remote attackers to execute arbitrary system commands with administrative privileges. The flaw stems from an alternate path authentication bypass (CWE-288) in the management interface daemons.
TL;DR
Unauthenticated remote command execution on Check Point Security Management Servers via alternate path authentication bypass (CWE-288), CVSS 9.3.
Technical Details
- CWE ID: CWE-288
- Attack Vector: Network
- CVSS: 9.3
- EPSS: Not assigned
- Impact: Arbitrary Command Execution / Full Compromise
- Exploit Status: None
- KEV Status: Not Listed
Affected Systems
- Check Point Security Management Server
- Check Point Multi-Domain Security Management Server (MDS)
-
Check Point Security Management Server / MDS: R81.20 (Fixed in:
R81.20 Jumbo HFA Take 161) -
Check Point Security Management Server / MDS: R82 (Fixed in:
R82 Jumbo HFA Take 122) -
Check Point Security Management Server / MDS: R82.10 (Fixed in:
R82.10 Jumbo HFA Take 40)
Mitigation Strategies
- Apply Jumbo Hotfix Accumulator updates for R81.20, R82, or R82.10 immediately.
- Restrict administrative GUI clients (Trusted Clients) in SmartConsole to authorized IPs.
- Isolate administrative ports (TCP 18190, 443, 19009) from untrusted networks and the public internet.
Remediation Steps:
- Identify current software version and Jumbo Hotfix Take running on the Security Management Server or Multi-Domain Server.
- For R82.10, install Jumbo Hotfix Accumulator starting from Take 40.
- For R82, install Jumbo Hotfix Accumulator starting from Take 122.
- For R81.20, install Jumbo Hotfix Accumulator starting from Take 161.
- For legacy versions (R81.10, R81, R80.x), upgrade to a supported release first.
- Open SmartConsole, navigate to Manage & Settings > Permissions & Administrators > Trusted Clients, and restrict access to authorized administration hosts.
- Apply firewall rules to enforce network-level restrictions on administrative ports.
References
- Check Point Support Advisory sk185222
- Official CVE Record on CVE.org
- Check Point Gateway and Management Hardening Guide
- Jumbo Hotfix Accumulator for R82.10 Home Page
- Jumbo Hotfix Accumulator for R82 Home Page
- Jumbo Hotfix Accumulator for R81.20 Home Page
Read the full report for CVE-2026-18574 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)