What's Happening?
Check Point has issued security updates to address a high-severity authentication-bypass vulnerability identified as CVE-2026-18574. This flaw could allow attackers to fully compromise vulnerable Security Management environments. The vulnerability affects
both Security Management Server and Multi-Domain Security Management Server deployments across several Check Point releases, including versions R80, R80.10, R80.20, R80.30, R80.40, R81, and R81.10, which have reached their end of support. Supported versions impacted include R81.20, R82, and R82.10. An unauthenticated attacker with network access to the targeted management server can bypass authentication and execute arbitrary commands, potentially leading to a complete takeover of the system. Check Point has confirmed that Smart-1 Cloud customers are protected from this issue and has found no evidence of active exploitation. The company has released fixes through Jumbo Hotfix Accumulator updates.
Why It's Important?
The vulnerability poses a significant risk to organizations using Check Point's Security Management systems, as it could allow attackers to alter security policies, create privileged accounts, or disable protections. Given that these systems typically hold privileged access to enterprise firewall configurations and security policy controls, a successful attack could have severe implications for an organization's security posture. Prompt patching is essential to mitigate the risk, especially for organizations that do not restrict Trusted Clients or expose management services to untrusted networks. The release of these updates underscores the importance of maintaining up-to-date security measures and the potential consequences of vulnerabilities in critical infrastructure.
What's Next?
Organizations using unsupported versions of Check Point's software are advised to upgrade to supported releases to ensure they receive necessary security patches. Administrators should also review and restrict Trusted Clients in SmartConsole to approved IP addresses and subnets, install updated security policies, and limit management connectivity to trusted workstations. Security teams are encouraged to monitor logs for unusual activity that could indicate compromise attempts. Enterprises should prioritize applying the relevant Check Point hotfixes to protect against potential exploitation of this vulnerability.











