Description
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.
Published: 2026-08-03
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication bypass flaw (CWE‑288) allows an unauthenticated remote attacker with network access to the Management services to execute arbitrary system commands on the Check Point Security Management Server. Successful exploitation can lead to a full compromise of the security management system, effectively giving the attacker unlimited administrative control without proper authentication.

Affected Systems

The vulnerability affects Check Point Multi‑Domain Security Management Server and Check Point Security Management Server. No specific version information is provided in the CVE data.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. The attack requires network connectivity to the Management services, implying a network‑based vector. Once authenticated bypass is achieved, arbitrary commands can be run with the privileges of the Security Management Server process.

Generated by OpenCVE AI on August 4, 2026 at 10:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch released by Check Point that addresses CVE‑2026‑18574
  • Configure firewall or network segmentation to restrict Management service access to trusted IP ranges or VPN only
  • Disable or remove any unused remote authentication methods that expose the Management console to external networks

Generated by OpenCVE AI on August 4, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Checkpoint
Checkpoint multi-domain Security Management Server
Checkpoint security Management Server
Vendors & Products Checkpoint
Checkpoint multi-domain Security Management Server
Checkpoint security Management Server

Mon, 03 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.
Title Authentication Bypass in Check Point Security Management Server
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Checkpoint Multi-domain Security Management Server Security Management Server
cve-icon MITRE

Status: PUBLISHED

Assigner: checkpoint

Published:

Updated: 2026-08-05T03:56:59.065Z

Reserved: 2026-08-02T06:50:57.353Z

Link: CVE-2026-18574

cve-icon Vulnrichment

Updated: 2026-08-03T13:16:53.154Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-03T13:17:13.000

Modified: 2026-08-05T05:16:47.433

Link: CVE-2026-18574

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T10:30:07Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel