CVE-2026-18574: A Critical Authentication Bypass Vulnerability in Check Point’s Security Management Server

05 Aug 2026

Check Point has recently disclosed a critical vulnerability in its Security Management Server and Multi-Domain Security Management Server (MDS) that can allow unauthenticated attackers with network access to execute arbitrary commands on vulnerable management servers.

 

Through this blog, we will understand what the authentication bypass flaw in Check Point’s security management server is about and some of the security actions that organizations can take to prevent/respond to the threat.  

About the vulnerability

Vendor + component affected 

Potentially exposed environments 

About  

CVSS score 

 Check Point Software Technologies Ltd. 

+ 

Check Point Security Management Server & Multi-Domain Security Management Server (MDS) 

 

 

 

 

 

 

 

Organizations with management interfaces exposed to untrusted networks or with overly permissive Trusted Client configurations 

 

An authentication bypass vulnerability can allow attackers  

9.3 (Critical) 

What can attackers do with the vulnerability?

Attackers can exploit the vulnerability to:

 

  • Bypass authentication mechanisms without valid credentials
  • Execute arbitrary commands to install malware, steal data or take control of the system
  • Cause a complete compromise of the Check Point Security Management environment
  • Make unauthorized modification of firewall and security policies
  • Take administrative control over centrally managed gateways
  • Gain unauthorized access to sensitive security configurations
  • Laterally move into protected internal network segments
  • Disrupt enterprise security operations

SharkStriker’s recommendations

SharkStriker recommends implementing the following:

 

  • Apply the latest Check Point Jumbo Hotfix Accumulator immediately.
  • Upgrade unsupported Check Point Security Management Server versions to supported releases.
  • Review and tighten Trusted Client configurations.
  • Restrict administrative access to dedicated management workstations and trusted networks only.
  • Ensure Security Management interfaces are never exposed to the Internet.
  • Audit recent administrative activity and security policy changes for unauthorized modifications.
  • Continuously monitor authentication logs and management server activity for suspicious behavior.

SharkStriker’s Actions

  • Validated Intelligence.
  • Initiated a customer impact assessment.
  • Prepared an advisory for the affected customers.
  • Notified the detection engineering team to review monitoring coverage.
  • Recommended threat hunting for suspicious authentication attempts and unauthorized administrative activity targeting Check Point Management Servers.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE