Check Point has released security updates for a high-severity authentication-bypass vulnerability (CVE-2026-18574) that could allow attackers to compromise vulnerable Security Management environments fully.
This issue affects both Security Management Server and Multi-Domain Security Management Server deployments across several Check Point releases.
According to Check Point, an unauthenticated attacker with network access to the targeted management server can bypass Management authentication and execute arbitrary commands.
A successful attack could result in a complete takeover of the Security Management system, jeopardizing firewall policies, gateway configurations, administrator access, and the managed security infrastructure.
The vulnerability impacts versions R80, R80.10, R80.20, R80.30, R80.40, R81, and R81.10, all of which have reached their end of support. Supported affected versions include R81.20, R82, and R82.10.
Check Point Authentication Bypass Flaw
Check Point has confirmed that Smart-1 Cloud customers are already protected from this issue. The company stated that it discovered CVE-2026-18574 internally and has found no evidence of active exploitation in the wild.
However, the potential impact makes prompt patching essential, as Security Management Servers typically hold privileged access to enterprise firewall configurations and security policy controls. Exploitation of this vulnerability requires network connectivity to the Check Point Security Management Server.
Organizations are at increased risk if they do not restrict Trusted Clients, allow GUI client connections from broad network ranges, or expose management services to untrusted networks. Management interfaces should never be directly accessible from the public internet or unrestricted user networks.
Check Point has addressed the flaw through Jumbo Hotfix Accumulator updates. The fixes are available in Jumbo Hotfix Accumulator Take 404040 for R82.10, Take 122122122 for R82, and Take 161161161 for R81.20.
Organizations using unsupported R80 and early R81 versions should prioritize upgrading to a supported release, as patches may not be available for these end-of-support versions.
Until patches can be deployed, Check Point recommends restricting Trusted Clients in SmartConsole to approved administrative IP addresses and subnets.
Administrators should avoid using “Any” as a Trusted Client definition, install the updated security policy after making changes, and limit Management connectivity to dedicated trusted administrator workstations.
Security teams should also ensure that firewall policies restrict management access, implied rules protecting control connections remain enabled, and Management services are not exposed to untrusted networks.
Reviewing logs for unusual management connections, unexpected administrator activity, or suspicious command execution can help detect potential compromise attempts.
Since a Security Management Server serves as a central control plane, a compromise could allow an attacker to alter security policies, create privileged accounts, turn off protections, or pivot into managed environments. Enterprises should treat CVE-2026-18574 as a priority remediation issue and apply the relevant Check Point hotfix without delay.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

