CVE-2026-18574: Authentication Bypass in Check Point Security Management Server
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18574?
The severity of CVE-2026-18574 is classified as critical with a CVSS score of 9.3.
How do I fix CVE-2026-18574?
To fix CVE-2026-18574, apply the security updates provided by Check Point for the affected Security Management Server products.
What type of vulnerability is CVE-2026-18574?
CVE-2026-18574 is an authentication bypass vulnerability that allows unauthorized access to Management services.
Who is affected by CVE-2026-18574?
CVE-2026-18574 affects users of Check Point Security Management Server and Check Point Multi-Domain Security Management Server (MDS).
What can attackers do with CVE-2026-18574?
Attackers exploiting CVE-2026-18574 can execute arbitrary commands on the Security Management Server without authentication.