Critical authentication bypass in Check Point management servers

Check Point disclosed a critical vulnerability on 1 August 2026 in Security Management Server and Multi-Domain Security Management Server. The flaw is tracked as CVE-2026-18574 and scored at 9.3 under CVSS. An attacker without login, but with network access to a vulnerable server, can execute arbitrary commands and in the worst case gain full control of the management environment. Smart-1 Cloud customers have already been patched. Check Point states that the vulnerability was found internally, and that neither active exploitation nor publicly available exploit code has been reported.

What happens technically

A Check Point management server is not the firewall itself, but the system that controls it. It holds the rule base, the configuration and the logs for the environment, and it distributes changes out to the devices that enforce them. The server therefore carries a trust no single firewall holds on its own.

The vulnerability is described as an authentication bypass. In short, a request slips past the check of who the sender is, and is handled as though it came from an authorised user. Check Point states that the consequence may be execution of arbitrary commands and potentially full control of the management environment. The vendor has not published technical details of the flaw itself, which is ordinary practice while customers get time to update. A score of 9.3 belongs to the top band in CVSS, and scores in that band are usually given when the attack can happen over the network without prior access and with severe consequences. Check Point additionally recommends restricting who may reach the management interface, through Trusted Clients and network controls.

Attackerwithout a loginManagement serverauthentication bypassedArbitrary commandsrun on the serverControlof the management environment
Figure: The attack requires no login, only network access to the server. Closing the interface therefore matters as much as installing the update.

What this means for you if you have Check Point deployed

The order of work is the point here, and in our view it is what you should settle before anything else. If you have a management server reachable from the internet, that is a target which hands the attacker control of your defence itself. Many organisations have opened management access from outside over time, often so that a supplier could reach it. The opening stays there, and nobody thinks about it again. This advisory is in our view a good occasion to close it.

The second point is accountability. If a partner operates your firewall environment, you still carry the risk. You then need it settled who watches the vendor's security advisories. You also need it settled who decides on updating, and how quickly that happens. Check Point finding the flaw itself, with no exploitation reported, gives you breathing room. We would not call it an excuse to wait. If your organisation is covered by NIS2, this is both vulnerability handling and supplier management under Article 21.

Berigo recommends

  • Install the security update from Check Point, and use advisory sk185222 to identify the affected versions.
  • Close the management interface to the internet, and restrict access to named addresses with Trusted Clients.
  • Have the operations supplier confirm in writing that the update is complete, with a date.
  • Review the logs on the management server for logins and rule base changes over the recent period.
  • Set up a standing routine for catching security advisories from the vendors of your security equipment.

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch