TL;DR: Check Point patched a Check Point authentication bypass affecting its Security Management and Multi-Domain Security Management servers. Tracked as CVE-2026-18574, the flaw carries a CVSS score of 9.3. Check Point found the issue internally and reports no active exploits.
- CVE: CVE-2026-18574
- CVSS: 9.3 (Critical · CVSSv4)
- Product: checkpoint Security Management Server
- Affected: R82.10 with Jumbo Hotfix Accumulator Take 39 or below, R82 with Jumbo Hotfix Accumulator Take 121 or below, R81.20 with Jumbo Hotfix Accumulator Take 160 or below, R81.10, R81, R80.40 (+4 more)
- Impact: Authentication Bypass in Check Point Security Management Server
- Status: No confirmed exploitation yet
- Action: See vendor advisory
Why it matters
An unauthenticated attacker who reaches the flaw could execute arbitrary commands on the Security Management Server. Check Point’s advisory states that successful exploitation could result in full compromise of the Security Management system. That system sits at the top of the trust hierarchy, since it controls policy across every connected gateway.
A compromised Management Server could let an attacker rewrite firewall rules, alter administrator permissions, or disable logging across an entire deployment. Check Point has patched similar Management-tier authentication bypasses before, some of which attackers later exploited in the wild. That history makes fast patching worthwhile even without confirmed exploitation this time.
How the attack works
Exploitation requires network access to the Security Management Server. Check Point’s advisory notes that environments exposing Management services to untrusted networks, or that fail to restrict Trusted Clients, face increased exposure to the Check Point authentication bypass.
Exploitation status
Check Point states plainly that this issue was discovered internally, and the company has no indication of active exploits at this time.
Affected versions and patch
The flaw affects R80 through R81.10, all now end of support, plus currently supported R81.20, R82, and R82.10. Smart-1 Cloud customers are already protected. Fixes ship in the Jumbo Hotfix Accumulator for each supported branch. Administrators should review the full advisory and apply the hotfix, and restrict Trusted Clients to authorized hosts in the meantime.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.