Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5496 articles · 220883 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-18574PATCHED
checkpoint · security management server

Authentication Bypass in Check Point Security Management Server

Description

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.

Affected Products

VendorProductVersions
checkpointsecurity management serverR82.10 with Jumbo Hotfix Accumulator Take 39 or below, R82 with Jumbo Hotfix Accumulator Take 121 or below, R81.20 with Jumbo Hotfix Accumulator Take 160 or below, R81.10, R81, R80.40, R80.30, R80.20, R80.10, R80, R82.10 with Jumbo Hotfix Accumulator Take 39 or below, R82 with Jumbo Hotfix Accumulator Take 121 or below, R81.20 with Jumbo Hotfix Accumulator Take 160 or below, R81.10, R81, R80.40, R80.30, R80.20, R80.10, R80

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
check pointsecurity managementcert_advisory90%

References

  • https://support.checkpoint.com/results/sk/sk185222(vendor-advisory)

Related News (7 articles)

Tier D
The Hacker News5d ago
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
→ No new info (linked only)
Tier B
CERT-FR43d ago
Bulletin d'actualité CERTFR-2026-ACT-034 (10 août 2026)
→ No new info (linked only)
Tier B
CCCS Canada49d ago
Checkpoint security advisory (AV26-774)
→ No new info (linked only)
Tier D
Heise Security49d ago
Check Point: Angreifer können Security-Management-Server übernehmen
→ No new info (linked only)
Tier B
BSI Advisories49d ago
[NEU] [hoch] Check Point Security Management: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Codeausführung
→ No new info (linked only)
Tier B
CERT-FR49d ago
Vulnérabilité dans les produits Check Point (04 août 2026)
→ No new info (linked only)
Tier C
VulDB50d ago
CVE-2026-18574 | Check Point Security Management Server up to R81.10 Management Services improper authentication
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited❌ No
Patch available
https://support.checkpoint.com/results/sk/sk185222
CWECWE-288
PublishedAug 3, 2026
Trending Score35
Source articles7
Independent6
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-93616EXPKEV
Directory Traversal and File upload allows execution of arbitrary script on the Management Server
Trending: 112
CRITICALCVE-2026-91843
Stack overflow in login process to the Security Management and Log Servers
Trending: 66
NONECVE-2026-16232EXP
Authentication Bypass in the SmartConsole Login Process Using an Application Token
Trending: 54
CRITICALCVE-2026-85103
Heap-based Buffer Overflow in VPN Certificate ASN.1 Decoding
Trending: 48
CRITICALCVE-2026-62144
Management Authentication Bypass and Privilege Escalation
Trending: 39

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 3, 2026
Discovered by ZDM
Aug 3, 2026
Patch Available
Aug 5, 2026