Authentication Bypass Vulnerability in Check Point Security Management Server
CVE-2026-18574

9.3CRITICAL

What is CVE-2026-18574?

An authentication bypass vulnerability exists in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that may allow an unauthenticated remote attacker to access Management services and execute arbitrary commands. This vulnerability poses a significant risk as successful exploitation could lead to full system compromise. Check Point has identified this issue through internal measures and reports no evidence of active exploitation at this time.

Affected Version(s)

Multi-Domain Security Management Server R82.10 with Jumbo Hotfix Accumulator Take 39 or below

Multi-Domain Security Management Server R82 with Jumbo Hotfix Accumulator Take 121 or below

Multi-Domain Security Management Server R81.20 with Jumbo Hotfix Accumulator Take 160 or below

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.