External risk intelligence

Check Point Management Server Authentication Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-18574

The vulnerability affects Security Management Servers. While these are critical infrastructure components, they are typically deployed within internal management networks and are not intended to be exposed directly to the public internet, though remote management access can sometimes lead to inadvertent or configured network reachability.

Authentication Bypass

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An authentication bypass vulnerability has been identified in Check Point Security Management and Multi-Domain Security Management Servers. This issue could permit an unauthenticated remote attacker to execute arbitrary commands, potentially leading to a full compromise of the security management system. Check Point has indicated that there is no current evidence of this vulnerability being actively exploited.

  • Unauthenticated attackers could take control of security management.
  • Protects core network security infrastructure from compromise.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated remote attacker with network access to management services can bypass authentication and execute arbitrary commands on the Check Point Security Management Server, potentially leading to a full compromise of the system.

  • Unauthenticated remote network access required.
  • Bypasses authentication to trigger vulnerability.
  • Full compromise of management system.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated remote attacker with network access to management services could bypass authentication and execute arbitrary commands on the Security Management Server, potentially leading to a full compromise of the system. This could occur when management services are accessible over the network.

  • Security management system data.
  • Remote network access to services.
  • Full system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This authentication bypass vulnerability impacts Check Point Security Management Servers and Multi-Domain Security Management Servers, potentially allowing remote attackers to execute arbitrary commands and achieve full system compromise. Given these are critical management systems, the initial focus should be on identifying their presence within your environment, confirming network exposure, and locating the accountable owner for risk-based remediation planning.

  • Security management teams own the issue.
  • Verify network exposure and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Check Point Security Management Server?

It is a centralized platform used by administrators to manage and configure firewall policies, security gateways, and security objects across an organization's network infrastructure. The Multi-Domain variant extends this capability to support multiple independent security environments from a single management framework.

What does CVE-2026-18574 mean?

This CVE represents an authentication bypass, classified as CWE-288. In simple terms, the software has a flaw that allows someone to interact with restricted management functions without first proving their identity. Because this affects the management server, an attacker who successfully uses this can issue commands as if they were a legitimate administrator.

How does an attacker trigger this vulnerability?

The vulnerability requires the attacker to have direct network access to the management services of the affected Check Point server. It is not triggered by user-level actions like opening a file or visiting a website. If the management interface is isolated from the network or restricted via access control lists, the attacker cannot reach the vulnerable service.

Is my organization at risk for CVE-2026-18574?

Risk depends on your network architecture. According to Halo Surface Signal, these servers are critical infrastructure usually housed in internal management networks. While they are not designed to face the public internet, you should verify if any management ports are inadvertently reachable from broader or untrusted network segments.

How should I respond to this threat advisory?

Your first step is to locate all instances of Check Point Security Management and Multi-Domain Security Management Servers within your environment. Once identified, confirm their network connectivity status and ensure they are not accessible to unauthorized users. Consult your internal security management team to prioritize remediation planning based on these findings.

References