Check Point Security Management Authentication Bypass (CVE-2026-18574) — Unauthenticated Remote Command Execution on Security Management Server — Threadlinqs Intelligence
As of 2026-08-04, Check Point Security Management Authentication Bypass (CVE-2026-18574) — Unauthenticated Remote Command Execution on Security Management Server is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 4 indicators of compromise.
Threat ID: TL-2026-1855 · Severity: CRITICAL · CVSS: 9.3 · Status: ACTIVE · Category: VULNERABILITY
CVE-2026-18574 is a critical authentication bypass vulnerability (CWE-288, CVSS 9.3) in Check Point Security Management Server and Multi-Domain Security Management Server (MDS). An unauthenticated
CVE-2026-18574 is an authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS), classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) with a CVSS v4.0 score of 9.3 (Critical). The vulnerability resides in the management authentication path of the FWM/CPMI service (TCP 18190) and/or CPM Web Services (TCP 19009), where an unauthenticated remote attacker with network access to Management services can bypass the authentication mechanism and execute arbitrary commands on the Security Management Server.
Based on the related and architecturally similar CVE-2026-16232 (SmartConsole authentication bypass, exploited in the wild as a zero-day and added to CISA KEV on July 22, 2026), the underlying class of vulnerability involves a broken trust boundary in the application authentication path. In the CPMI protocol, authentication relies on SIC (Secure Internal Communication) certificates for mutual authentication between management components. When the vulnerable code path accepts an attacker-controlled Distinguished Name (DN) as the identity of a remote application without validating it against the authenticated peer certificate's subject DN, a remote attacker can replay the server's own SIC DN obtained during unauthenticated bootstrap communication, obtain an application login token, mint a SmartConsole SSO ticket claiming system_admin identity, and redeem it for a full administrator session.
The attack requires network access to the Security Management Server but does not require authentication, user interaction, or any special conditions. The SSVC assessment from CISA ADP classifies the vulnerability as automatable with total technical impact, meaning it is scriptable and bot-friendly for mass exploitation. The attack surface is amplified in environments where Trusted Clients are configured as 'Any' (unrestricted), GUI client connections are allowed from broad IP ranges, or Management services are exposed to untrusted networks.
Successful exploitation enables an attacker to achieve full compromise of the Security Management system, with the capability to: alter security policies and firewall rules across all managed gateways, create privileged administrator accounts (backdoor accounts), disable logging and monitoring to conceal activity, modify or delete VPN configurations, execute commands on managed security gateways, access stored credentials and configuration data, establish persistence on the management server, and pivot laterally into managed network environments. As the management server is the central control plane for the entire Check Point firewall deployment, its compromise effectively gives the attacker control over the entire managed security infrastructure.
The vulnerability affects all Check Point Security Management Server and MDS versions from R80 through R82.10, spanning both end-of-support (R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10) and currently supported (R81.20, R82, R82.10) branches. For supported versions, Check Point has released fixes via Jumbo Hotfix Accumulator updates: R82.10 Take 40+, R82 Take 122+, and R81.20 Take 161+. Smart-1 Cloud customers are already protected. For end-of-support versions (R81.10 and earlier), no patch is available and organizations must upgrade to a supported release. Compensating controls include restricting Trusted Clients to specific IP addresses/subnets (never 'Any'), implementing firewall rules to restrict management access to trusted admin workstations only, enabling implied rules for control connections, and ensuring management interfaces are never exposed to the public internet. This vulnerability is closely related to CVE-2026-16232 (Check Point SmartConsole auth bypass, CVSS 9.1, exploited in the wild), and is part of a broader cluster of Management-tier authentication bypass vulnerabilities Check Point patched in 2026, including CVE-2026-62144 (management auth bypas
Target sectors: government administration, finance, health, technology, telecoms, energy, defense, education, retail, manufacturing
Target regions: North America, Europe, Asia Pacific, Middle East, Latin America, Africa
Detections & IOCs
As of 2026-08-14, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 4 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-18574, T1190, T1059, T1098, T1136, T1685, T1552, T1087, T1082, T1005, T1570