[CIVN-2026-0395] Authentication Bypass Vulnerability in Check Point

By Published On: August 6, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Authentication Bypass Vulnerability in Check Point


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


Security Management Server, Multi-Domain Security Management Server versions R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10 (All End of Support), R81.20, R82, R82.10

Overview


A vulnerability has been reported in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) which may allow a remote unauthenticated attacker to bypass the Management authentication mechanism and execute arbitrary commands on the Security Management Server.


Target Audience:

Organizations and administrators using the affected Check Point Security Management Server and Multi-Domain Security Management Server (MDS).


Risk Assessment:

High risk of authentication bypass, arbitrary command execution, and complete compromise of the server.


Impact Assessment:

Authentication bypass, arbitrary command execution, unauthorized administrative access, and complete compromise of the Server.


Description


Check Point Security Management Server and Multi-Domain Security Management Server (MDS) are centralized management platforms used for administering and enforcing security policies across Check Point security gateways.


This vulnerability exists due to an authentication bypass flaw in the Management Server. An unauthenticated attacker with network access to the Management Server may exploit this vulnerability to bypass the authentication mechanism and execute arbitrary commands on the affected system.


Successful exploitation of this vulnerability could allow an attacker to gain unauthorized administrative access, execute arbitrary commands, and completely compromise the affected Check Point Security Management Server.


Solution


Users are advised to apply appropriate updates as mentioned:

https://support.checkpoint.com/results/sk/sk185222



Vendor Information


 

https://support.checkpoint.com/


References


 

https://support.checkpoint.com/results/sk/sk185222


CVE Name

CVE-2026-18574




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp0mbsACgkQ3jCgcSdc

ys9oNg//ebP9hrBHJujxj4IruBWg1Pt5VyN1w5HULC/2jh/e2OKLzPR98judzNlG

lUiJJNECYWxETbc0osiR30/YFgoPDfQG8cNVyOyeqeLDDA7ZQ1nWQd9oLRiL5qGF

7Dml+709nBL21wCGKJSEGHSwnDMXZOMflOhjbwV7tdx4vfMQn9L1MOBq1u91jj8c

jEwki9n2/KS26P611iWPnm493YNdLz7TePoEc0MHvQn+tmWkU8LhIsjWaC4e4aLg

4RP5DvOrDwtktlddOhmKo07vuB7qfhZnoAZUuidcEWKfg+LAT6L8QK2Vrl8oEwmv

0L5p7o3y/F6uUoaFqBavcwvDzUnpENks/0hZ2f01/izhwXegp7b2CDWT5aRdVOER

U0DMXy+5XbPwZp9vXI14SKp0IOy5FmjawAzdyTvolrUcOzrtoZIV7dDXr6zqpfbI

Ek1+LuMGYP2CS0IEY70UXH0mDKTkkuOb43Q2/BHnNMHJUYMj+XbgJfVcDxhMPNTg

kTpfs5F8uUF2vYBAwTT9zDXK4TZSy+hSDcqiIp2dlFhA19NaJkSRSSX28/fPpLN8

MpYSHFbqzAcYI3GHVUt2rAaLTWNQQvN753Ye0F7GdPHUZ0N5dDGkSTw/LO8NnJTe

d3Nz19KYdA4NitosHeFzH8hq7F2YGC2rDDCKp1cNwasQ3ISExSc=

=95jg

—–END PGP SIGNATURE—–

Share this article