Check Point Security Management Authentication Bypass (CVE-2026-18574) — Unauthenticated Remote Command Execution on Security Management Server

Check Point Security Management Authentication Bypass (TL-2026-1855) is a critical-severity software vulnerability scored CVSS 9.3, first published 2026-08-03. It has no confirmed attribution, affects Check Point Software Technologies Security Management Server, references 1 CVE (CVE-2026-18574), maps to 12 MITRE ATT&CK techniques (T1005, T1059, T1071), and is covered by 9 detection rules and 4 indicators of compromise.

Key facts for TL-2026-1855

Threat ID
TL-2026-1855
Severity
CRITICAL
CVSS
9.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-08-03
Last reviewed
2026-08-03
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, telecoms, energy, defense, education, retail, manufacturing
Target regions
North America, Europe, Asia Pacific, Middle East, Latin America, Africa
Detection rules
9
Indicators of compromise
4

CVE-2026-18574 is a critical authentication bypass vulnerability (CWE-288, CVSS 9.3) in Check Point Security Management Server and Multi-Domain Security Management Server (MDS). An unauthenticated remote attacker with network access to Management services can bypass authentication and execute arbitrary commands, leading to full compromise of the Security Management system — including control over all managed firewall gateways, security policies, administrator accounts, and logging infrastructure. Check Point discovered the vulnerability internally and released fixes via Jumbo Hotfix Accumulator updates for supported branches. No active exploitation has been reported at the time of disclosure, but the vulnerability is classified as automatable with total technical impact by CISA SSVC, and is closely related to CVE-2026-16232 (SmartConsole auth bypass) which was exploited in the wild as a zero-day and added to CISA KEV.

How Check Point Security Management Authentication Bypass works

CVE-2026-18574 is an authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS), classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) with a CVSS v4.0 score of 9.3 (Critical). The vulnerability resides in the management authentication path of the FWM/CPMI service (TCP 18190) and/or CPM Web Services (TCP 19009), where an unauthenticated remote attacker with network access to Management services can bypass the authentication mechanism and execute arbitrary commands on the Security Management Server.

Based on the related and architecturally similar CVE-2026-16232 (SmartConsole authentication bypass, exploited in the wild as a zero-day and added to CISA KEV on July 22, 2026), the underlying class of vulnerability involves a broken trust boundary in the application authentication path. In the CPMI protocol, authentication relies on SIC (Secure Internal Communication) certificates for mutual authentication between management components. When the vulnerable code path accepts an attacker-controlled Distinguished Name (DN) as the identity of a remote application without validating it against the authenticated peer certificate's subject DN, a remote attacker can replay the server's own SIC DN obtained during unauthenticated bootstrap communication, obtain an application login token, mint a SmartConsole SSO ticket claiming system_admin identity, and redeem it for a full administrator session.

The attack requires network access to the Security Management Server but does not require authentication, user interaction, or any special conditions. The SSVC assessment from CISA ADP classifies the vulnerability as automatable with total technical impact, meaning it is scriptable and bot-friendly for mass exploitation. The attack surface is amplified in environments where Trusted Clients are configured as 'Any' (unrestricted), GUI client connections are allowed from broad IP ranges, or Management services are exposed to untrusted networks.

Successful exploitation enables an attacker to achieve full compromise of the Security Management system, with the capability to: alter security policies and firewall rules across all managed gateways, create privileged administrator accounts (backdoor accounts), disable logging and monitoring to conceal activity, modify or delete VPN configurations, execute commands on managed security gateways, access stored credentials and configuration data, establish persistence on the management server, and pivot laterally into managed network environments. As the management server is the central control plane for the entire Check Point firewall deployment, its compromise effectively gives the attacker control over the entire managed security infrastructure.

The vulnerability affects all Check Point Security Management Server and MDS versions from R80 through R82.10, spanning both end-of-support (R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10) and currently supported (R81.20, R82, R82.10) branches. For supported versions, Check Point has released fixes via Jumbo Hotfix Accumulator updates: R82.10 Take 40+, R82 Take 122+, and R81.20 Take 161+. Smart-1 Cloud customers are already protected. For end-of-support versions (R81.10 and earlier), no patch is available and organizations must upgrade to a supported release. Compensating controls include restricting Trusted Clients to specific IP addresses/subnets (never 'Any'), implementing firewall rules to restrict management access to trusted admin workstations only, enabling implied rules for control connections, and ensuring management interfaces are never exposed to the public internet. This vulnerability is closely related to CVE-2026-16232 (Check Point SmartConsole auth bypass, CVSS 9.1, exploited in the wild), and is part of a broader cluster of Management-tier authentication bypass vulnerabilities Check Point patched in 2026, including CVE-2026-62144 (management auth bypass with gateway pivot, KEV-listed) and CVE-2026-62145 (Gaia Portal privilege escalation, KEV-listed).

MITRE ATT&CK techniques used in TL-2026-1855

Collection

T1005 Data from Local System

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol

Discovery

T1082 System Information Discovery; T1087 Account Discovery

Persistence

T1098 Account Manipulation; T1136 Create Account

Initial Access

T1190 Exploit Public-Facing Application

Credential Access

T1552 Unsecured Credentials

Impact

T1565 Data Manipulation

Lateral Movement

T1570 Lateral Tool Transfer

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Check Point Security Management Authentication Bypass

  • Check Point Software Technologies — Security Management Server
    Vulnerable versions: R82.10 (JHFA Take 39 or below); R82 (JHFA Take 121 or below); R81.20 (JHFA Take 160 or below); R81.10; R81; R80.40; R80.30; R80.20; R80.10; R80
    Fixed in: R82.10 (JHFA Take 40 or above); R82 (JHFA Take 122 or above); R81.20 (JHFA Take 161 or above)
  • Check Point Software Technologies — Multi-Domain Security Management Server (MDS)
    Vulnerable versions: R82.10 (JHFA Take 39 or below); R82 (JHFA Take 121 or below); R81.20 (JHFA Take 160 or below); R81.10; R81; R80.40; R80.30; R80.20; R80.10; R80
    Fixed in: R82.10 (JHFA Take 40 or above); R82 (JHFA Take 122 or above); R81.20 (JHFA Take 161 or above)
  • Check Point Software Technologies — Smart-1 Cloud
    Fixed in: All versions — already protected

Remediation for Check Point Security Management Authentication Bypass

Patches

  • R82.10: Apply Jumbo Hotfix Accumulator Take 40 or above
  • R82: Apply Jumbo Hotfix Accumulator Take 122 or above
  • R81.20: Apply Jumbo Hotfix Accumulator Take 161 or above
  • R81.10 and earlier: No patch available — upgrade to supported R81.20 or later
  • Smart-1 Cloud customers: No action required — already protected

Immediate actions

  • Restrict Trusted Clients in SmartConsole to specific approved IP addresses/subnets — never use 'Any' as the Trusted Client definition
  • Install updated security policy after making Trusted Client changes
  • Ensure management interfaces are not exposed to the public internet
  • Deploy firewall rules restricting access to management ports (TCP 18190, 19009, 18191, 5432) to only trusted admin workstations
  • Enable implied rules for control connections to block management access from non-authorized IPs

Workarounds

  • Restrict GUI client Trusted Clients to only authorized IP addresses
  • Use firewall rules to restrict management access to dedicated trusted admin workstations
  • Disable CPMI (port 18190) if not required for backward compatibility with pre-R80 gateways
  • Review and audit current administrator accounts and Trusted Client configurations
  • Monitor management audit logs for unusual patterns: unexpected application-token authentication, unknown admin account creation, policy changes without change tickets, disabled logging services

Longer-term hardening

  • Implement network segmentation — isolate management traffic on a dedicated management VLAN with jump-host access for remote administration
  • Enforce MFA / Identity Provider integration for all administrator access
  • Set SmartConsole idle timeout to 10 minutes and enable administrator account lockout after failed authentication attempts
  • Enforce strong administrator password policies (minimum 10 characters)
  • Implement centralized logging and SIEM monitoring for management-plane audit events
  • Establish a formal patch management process with emergency change windows for critical security fixes
  • For end-of-support versions (R81.10 and below), plan immediate upgrade to a supported branch

CVEs associated with Check Point Security Management Authentication Bypass

CVE-2026-18574

Weaknesses (CWE) in Check Point Security Management Authentication Bypass

CWE-288

Timeline of Check Point Security Management Authentication Bypass

  • Check Point disclosed CVE-2026-62144 (management auth bypass with gateway pivot, CVSS 9.3) and CVE-2026-62145 (Gaia Portal privilege escalation), both added to CISA KEV.
  • Check Point disclosed CVE-2026-16232 (SmartConsole auth bypass, CVSS 9.1) which was exploited in the wild as a zero-day. CISA added it to KEV with a 3-day remediation deadline. Rapid7 published detailed technical analysis and PoC code demonstrating the SIC DN replay attack chain.
  • CVE-2026-18574 was reserved by Check Point Software Technologies Ltd. as the assigner.
  • OpenCVE listed CVE-2026-18574 with full metadata: CVSS v4.0 vector, CWE-288 weakness, SSVC metrics, and Check Point vendor advisory reference.
  • NVD published CVE-2026-18574 with CVSS v4.0 9.3 (Critical) and CWE-288 classification. NVD has not yet assigned CVSS v3.1 or v2.0 scores.
  • Cybersecurity News and SecurityOnline published articles on CVE-2026-18574, noting the critical severity, the relationship to the recently exploited CVE-2026-16232, and the risk of firewall policy takeover.
  • Check Point released Jumbo Hotfix Accumulator updates for supported branches: R82.10 Take 40, R82 Take 122, R81.20 Take 161. Smart-1 Cloud customers already protected with no action needed.
  • CISA ADP added SSVC assessment to CVE-2026-18574: exploitation none, automatable yes, technical impact total. The vulnerability is not yet in CISA KEV.
  • Check Point published CVE-2026-18574 via security advisory sk185222, disclosing a critical authentication bypass vulnerability in Security Management Server and MDS affecting versions R80 through R82.10. CVSS v4.0 score of 9.3 (Critical).

Sources cited for Check Point Security Management Authentication Bypass

Threats related to Check Point Security Management Authentication Bypass

Detection coverage for TL-2026-1855

As of 2026-08-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1855 across Splunk SPL, Microsoft KQL and Sigma, covering 4 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats