HomeTopics 1Authentication SystemsCheck Point Warns of High-Severity Authentication Bypass That Could Give Attackers Full...

Check Point Warns of High-Severity Authentication Bypass That Could Give Attackers Full Management Access

Date:

Related stories

spot_imgspot_imgspot_imgspot_img

Check Point has disclosed a high-severity authentication-bypass vulnerability affecting its Security Management Server and Multi-Domain Security Management Server (MDS) products. The flaw, tracked as CVE-2026-18574, could allow an unauthenticated attacker with network access to bypass management authentication and execute arbitrary commands potentially leading to full compromise of the security management system.

The disclosure is particularly important because a compromised management server is not just another compromised asset. It can become the control point from which an attacker could potentially influence security policies, administrative operations and the wider environment that depends on it.

Check Point says the vulnerability was discovered internally and that it currently has no indication of active exploitation. Nevertheless, organizations running affected versions should treat the alert as a priority, particularly where management interfaces are reachable from untrusted networks or Trusted Clients are broadly configured.

What is CVE-2026-18574?

According to Check Point’s security advisory, CVE-2026-18574 is a management authentication bypass vulnerability.

In practical terms, a successful attack could allow an unauthenticated attacker to get past the normal authentication controls protecting the Security Management Server and then execute arbitrary commands on the affected system.

The potential impact is serious: full compromise of the Security Management system.

The vulnerability affects both Security Management Server and Multi-Domain Security Management Server (MDS) deployments. Check Point states that exploitation requires network access to the Security Management Server, meaning the attack is not necessarily exposed to every deployment in the same way.

The risk increases, however, when organizations fail to properly restrict management access or expose management services to networks that should not have access.

Which Check Point versions are affected?

The advisory covers the following versions:

  • R80 – End of Support
  • R80.10 – End of Support
  • R80.20 – End of Support
  • R80.30 – End of Support
  • R80.40 – End of Support
  • R81 – End of Support
  • R81.10 – End of Support
  • R81.20
  • R82
  • R82.10

The presence of multiple end-of-support releases in the affected list is an important warning for organizations operating legacy infrastructure. Older systems can be particularly difficult to patch, upgrade or replace, but leaving them exposed can create an increasingly attractive target for attackers.

Check Point also notes that Smart-1 Cloud customers are already protected.

Patches are available

Check Point says the vulnerability has been fixed in the following Jumbo Hotfix Accumulators:

  • R82.10: Take 40 and later
  • R82: Take 122 and later
  • R81.20: Take 161 and later

Organizations running these supported branches should verify their current Take level and move to the appropriate fixed release as soon as operationally possible.

For older, end-of-support versions, security teams should not assume that compensating controls are a permanent substitute for modernization. Where a direct fix is unavailable, migration to a supported platform should be evaluated as part of the organization’s broader risk-reduction strategy.

Why management servers are such a valuable target

Security management infrastructure sits in a uniquely sensitive position.

A firewall may protect a network, but the management system often determines how that firewall behaves. If an attacker compromises the management layer, the consequences can extend well beyond one server.

This is why management interfaces should be treated as high-value administrative assets and protected with stronger controls than ordinary user-facing systems.

The lesson from CVE-2026-18574 is straightforward: a security product is only as secure as the management plane that controls it.

Organizations should therefore apply the same discipline to management infrastructure that they apply to identity systems, privileged-access platforms and other critical administrative services.

For organizations looking to strengthen their broader cybersecurity posture, this is also a useful opportunity to review how privileged administrative access is designed across the enterprise.

The immediate risk: exposed management access

Check Point specifically highlights two areas that organizations should examine:

1. Trusted Clients

Organizations should restrict Trusted Clients – GUI clients used to access management services – to explicitly authorized IP addresses and networks.

Check Point recommends that organizations do not use “Any” as a Trusted Client definition.

This is an important distinction. Authentication controls are valuable, but they should not be the only barrier protecting a sensitive management interface. Network-level restrictions provide another layer that can prevent unauthorized systems from even reaching the service.

2. Management access through firewall policy

Management connectivity should be restricted through firewall policy and permitted only from trusted administrative workstations or networks.

Security teams should also verify that the implied rules protecting control connections are enabled and confirm that management services are not exposed to untrusted networks.

These controls are particularly important while organizations are completing patch deployment.

What this means for organizations in the Middle East and Africa

The vulnerability is global, but it deserves particular attention from organizations across the Middle East and Africa, where critical infrastructure, financial institutions, government agencies, telecommunications providers, energy companies and large enterprises increasingly depend on centralized security management platforms.

For organizations operating across multiple countries or business units, Multi-Domain Security Management environments can represent a particularly sensitive administrative layer. A compromise of management infrastructure could have implications that extend across multiple managed environments.

The alert is also a reminder that cybersecurity teams should maintain accurate inventories of security infrastructure not just servers, endpoints and applications. Security management systems themselves must be included in vulnerability management programs, asset inventories and incident-response plans.

For CISOs and security leaders, the question should not simply be “Are we running Check Point?” It should be:

“Which version are we running, where is the management interface reachable from, who can access it, and have we verified that it is protected?”

10 actions security teams should take now

1. Identify all affected Check Point deployments

Create an inventory of Security Management Servers and MDS systems and verify the exact product version and Jumbo Hotfix level.

2. Apply the available security fixes

For supported versions, deploy the fixed Jumbo Hotfix Accumulator:

  • R82.10 Take 40 or later
  • R82 Take 122 or later
  • R81.20 Take 161 or later

Follow your organization’s change-management and testing procedures, but do not unnecessarily delay remediation.

3. Restrict Trusted Clients

Review the Trusted Clients configuration and limit GUI access to authorized IP addresses and networks. Avoid broad definitions such as “Any.”

4. Protect management access with firewall policy

Allow management connectivity only from trusted administrative workstations and approved networks.

5. Verify management services are not internet-facing

Review firewall rules, routing and network exposure to confirm that management services cannot be reached from untrusted networks.

6. Review implied rules protecting control connections

Confirm that the security controls intended to protect management and control connections are enabled and functioning as expected.

7. Monitor for suspicious activity

Review Security Management Server logs for unusual authentication attempts, unexpected administrative activity, command execution or access from unfamiliar IP addresses.

Although Check Point says it has no indication of active exploitation of CVE-2026-18574, organizations should still investigate anomalies rather than assuming they are unrelated.

8. Segment the management network

Keep security management infrastructure isolated from ordinary user, guest and other less-trusted networks wherever possible.

9. Review legacy systems and upgrade plans

If your organization is running an end-of-support release, treat this as a signal to accelerate migration toward supported software and infrastructure.

10. Strengthen administrator awareness

Ensure security administrators understand secure management practices, least privilege, network restrictions and the risks associated with exposed administrative interfaces. Organizations can also consider cybersecurity training and awareness programs to reinforce secure administrative practices.

The bigger lesson: protect the control plane

CVE-2026-18574 is a reminder that attackers do not always need to break through the front door of an organization. Sometimes, the more valuable target is the system that controls the doors.

The management plane is often trusted by the rest of the security architecture. If that layer is compromised, an attacker may gain a powerful position from which to manipulate defenses rather than simply bypass them.

That makes management systems an essential part of every organization’s cybersecurity risk management strategy.

The immediate priority for Check Point customers is clear: identify affected systems, apply the appropriate fixes, restrict management access and investigate any signs of suspicious activity.

There is currently no indication from Check Point that CVE-2026-18574 is being actively exploited. But organizations should not wait for exploitation to begin before protecting a system that sits at the heart of their security infrastructure.

Conclusion

Check Point’s disclosure of CVE-2026-18574 should put Security Management Server and MDS administrators on alert.

The vulnerability can potentially allow an unauthenticated attacker with network access to bypass management authentication and execute arbitrary commands, creating the possibility of full compromise of the affected management system.

The good news is that fixes are available for supported versions, and Check Point’s recommended network restrictions can significantly reduce exposure while remediation is underway.

For security teams, the message is simple: patch the management plane, restrict who can reach it, eliminate unnecessary exposure and monitor it as closely as any other privileged system.

Source: Check Point Security Advisory – CVE-2026-18574. Check Point’s advisory states that the issue was discovered internally and that the company has no indication of active exploitation. The advisory was last modified on August 3, 2026. (NVD)

Related reading: Explore more vulnerability and threat intelligence coverage on CyberCory.

Feature image set

I created the requested realistic, magazine-style visual treatment with three supporting feature images for this article, including the CVE alert, a security operations environment, and a patching-focused visual.

Ouaissou DEMBELE
Ouaissou DEMBELE
Ouaissou DEMBELE is a seasoned cybersecurity expert with over 12 years of experience, specializing in purple teaming, governance, risk management, and compliance (GRC). He currently serves as Co-founder & Group CEO of Sainttly Group, a UAE-based conglomerate comprising Saintynet Cybersecurity, Cybercory.com, and CISO Paradise. At Saintynet, where he also acts as General Manager, Ouaissou leads the company’s cybersecurity vision—developing long-term strategies, ensuring regulatory compliance, and guiding clients in identifying and mitigating evolving threats. As CEO, his mission is to empower organizations with resilient, future-ready cybersecurity frameworks while driving innovation, trust, and strategic value across Sainttly Group’s divisions. Before founding Saintynet, Ouaissou held various consulting roles across the MEA region, collaborating with global organizations on security architecture, operations, and compliance programs. He is also an experienced speaker and trainer, frequently sharing his insights at industry conferences and professional events. Ouaissou holds and teaches multiple certifications, including CCNP Security, CEH, CISSP, CISM, CCSP, Security+, ITILv4, PMP, and ISO 27001, in addition to a Master’s Diploma in Network Security (2013). Through his deep expertise and leadership, Ouaissou plays a pivotal role at Cybercory.com as Editor-in-Chief, and remains a trusted advisor to organizations seeking to elevate their cybersecurity posture and resilience in an increasingly complex threat landscape.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img