<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Check Point Patches Critical Auth Bypass That Could Hand Attackers Full Control of Security Systems

Urgent hotfix for Check Point flaw CVE-2026-18574: patch now to prevent authentication bypass and potential firewall control loss.
Content Team

Check Point has released hotfix updates for a critical authentication bypass flaw (CVE-2026-18574, CVSS 9.3) affecting its Security Management Server and Multi-Domain Security Management Server products. An unauthenticated attacker with network access can bypass authentication and execute arbitrary commands — potentially taking complete control of firewall policies, gateway configurations, and admin access.

Supported versions R81.20, R82 and R82.10 are fixed via Jumbo Hotfix Accumulator updates, listed in Check Point advisory sk185222. Smart-1 Cloud customers are already protected. Older R80 and early R81 releases are also affected but have hit end-of-support and will not receive patches — those instances need upgrading to a supported version.

Until you can patch, Check Point advises restricting Trusted Clients to approved administrative IP addresses and never using "Any" as a client definition. Check Point found the flaw internally and has seen no active exploitation yet — but given the stakes, patching now is non-negotiable.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo