CVE-2026-18574
Check Point · Security Management Server and Multi-Domain Security Management Server
An authentication bypass vulnerability in Check Point Security Management Server allows unauthenticated remote attackers to execute arbitrary commands.
Executive summary
A critical authentication bypass vulnerability in Check Point Security Management Server enables unauthenticated remote code execution, posing a risk of full system compromise.
Vulnerability
This is an authentication bypass vulnerability (CWE-288) that allows an unauthenticated remote attacker with network access to management services to execute arbitrary commands on the server.
Business impact
With a CVSS score of 9.3, this vulnerability represents an imminent threat to the security infrastructure. An attacker gaining control of the Security Management Server can manipulate firewall policies, intercept traffic, or disable security protections, resulting in a total compromise of the managed network environment.
Remediation
Immediate Action: Update the affected Check Point Security Management Server or Multi-Domain Security Management Server to the version specified in the vendor security advisory (SK185222).
Proactive Monitoring: Review audit logs for unauthorized command execution or unusual administrative activity originating from non-management interfaces.
Compensating Controls: Isolate the management interface from the public internet and restrict access to authorized administrative workstations using a VPN or jump host.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability is highly critical and requires immediate attention. Security teams should prioritize patching the management servers as per the guidance in the official vendor advisory to prevent potential unauthorized remote code execution.