
[CIVN-2026-0395] Authentication Bypass Vulnerability in Check Point
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Authentication Bypass Vulnerability in Check Point
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Security Management Server, Multi-Domain Security Management Server versions R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10 (All End of Support), R81.20, R82, R82.10
Overview
A vulnerability has been reported in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) which may allow a remote unauthenticated attacker to bypass the Management authentication mechanism and execute arbitrary commands on the Security Management Server.
Target Audience:
Organizations and administrators using the affected Check Point Security Management Server and Multi-Domain Security Management Server (MDS).
Risk Assessment:
High risk of authentication bypass, arbitrary command execution, and complete compromise of the server.
Impact Assessment:
Authentication bypass, arbitrary command execution, unauthorized administrative access, and complete compromise of the Server.
Description
Check Point Security Management Server and Multi-Domain Security Management Server (MDS) are centralized management platforms used for administering and enforcing security policies across Check Point security gateways.
This vulnerability exists due to an authentication bypass flaw in the Management Server. An unauthenticated attacker with network access to the Management Server may exploit this vulnerability to bypass the authentication mechanism and execute arbitrary commands on the affected system.
Successful exploitation of this vulnerability could allow an attacker to gain unauthorized administrative access, execute arbitrary commands, and completely compromise the affected Check Point Security Management Server.
Solution
Users are advised to apply appropriate updates as mentioned:
https://support.checkpoint.com/results/sk/sk185222
Vendor Information
https://support.checkpoint.com/
References
https://support.checkpoint.com/results/sk/sk185222
CVE Name
CVE-2026-18574
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp0mbsACgkQ3jCgcSdc
ys9oNg//ebP9hrBHJujxj4IruBWg1Pt5VyN1w5HULC/2jh/e2OKLzPR98judzNlG
lUiJJNECYWxETbc0osiR30/YFgoPDfQG8cNVyOyeqeLDDA7ZQ1nWQd9oLRiL5qGF
7Dml+709nBL21wCGKJSEGHSwnDMXZOMflOhjbwV7tdx4vfMQn9L1MOBq1u91jj8c
jEwki9n2/KS26P611iWPnm493YNdLz7TePoEc0MHvQn+tmWkU8LhIsjWaC4e4aLg
4RP5DvOrDwtktlddOhmKo07vuB7qfhZnoAZUuidcEWKfg+LAT6L8QK2Vrl8oEwmv
0L5p7o3y/F6uUoaFqBavcwvDzUnpENks/0hZ2f01/izhwXegp7b2CDWT5aRdVOER
U0DMXy+5XbPwZp9vXI14SKp0IOy5FmjawAzdyTvolrUcOzrtoZIV7dDXr6zqpfbI
Ek1+LuMGYP2CS0IEY70UXH0mDKTkkuOb43Q2/BHnNMHJUYMj+XbgJfVcDxhMPNTg
kTpfs5F8uUF2vYBAwTT9zDXK4TZSy+hSDcqiIp2dlFhA19NaJkSRSSX28/fPpLN8
MpYSHFbqzAcYI3GHVUt2rAaLTWNQQvN753Ye0F7GdPHUZ0N5dDGkSTw/LO8NnJTe
d3Nz19KYdA4NitosHeFzH8hq7F2YGC2rDDCKp1cNwasQ3ISExSc=
=95jg
—–END PGP SIGNATURE—–


