Check Point Patches Critical Auth Bypass That Could Hand Attackers Full Control of Security Systems
Want more insights like this?
Check Point has released hotfix updates for a high-severity authentication bypass flaw (CVE-2026-18574) affecting its Security Management Server and Multi-Domain Security Management Server products. An unauthenticated attacker with network access can bypass authentication and execute arbitrary commands — potentially taking complete control of firewall policies, gateway configurations, and admin access.
Affected versions include R81.20, R82, and R82.10, with fixes available via Jumbo Hotfix Accumulator updates. Older R80 and early R81 versions have hit end-of-support and may not receive patches. Check Point found the flaw internally and has seen no active exploitation yet — but given the stakes, patching now is non-negotiable.
Source: Cybersecurity News