Authentication Bypass Vulnerability in Check Point Security Management Server
CVE-2026-18574
Key Information:
- Vendor
Checkpoint
- Vendor
- CVE Published:
- 3 August 2026
Badges
What is CVE-2026-18574?
An authentication bypass vulnerability exists in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that may allow an unauthenticated remote attacker to access Management services and execute arbitrary commands. This vulnerability poses a significant risk as successful exploitation could lead to full system compromise. Check Point has identified this issue through internal measures and reports no evidence of active exploitation at this time.
Affected Version(s)
Multi-Domain Security Management Server R82.10 with Jumbo Hotfix Accumulator Take 39 or below
Multi-Domain Security Management Server R82 with Jumbo Hotfix Accumulator Take 121 or below
Multi-Domain Security Management Server R81.20 with Jumbo Hotfix Accumulator Take 160 or below
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved