Check Point discloses authentication bypass in Security Management Servers
Check Point has disclosed a critical authentication bypass vulnerability, CVE-2026-18574, affecting nearly all versions of its Security Management Server and Multi-Domain Security Management Server. No patch is available yet.
This article was drafted with AI assistance from multiple sources and was reviewed and approved by a human editor before publication.
Check Point has disclosed a critical vulnerability in its Security Management Server and Multi-Domain Security Management Server (MDS) products. The issue, tracked as CVE-2026-18574, is described as a Management Authentication Bypass, potentially allowing attackers to circumvent authentication mechanisms. The company published advisory AV26-774 on August 3, 2026, and the Canadian Centre for Cyber Security (Cyber Centre) has also issued a corresponding advisory, referencing Check Point support article sk185222.
The vulnerability affects a wide range of versions across both product lines. For the Security Management Server, affected versions include R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10, and R81.20 with Jumbo Hotfix Accumulator Take 160 or below, as well as R82 with Take 121 or below and R82.10 with Take 39 or below. The same version list applies to the Multi-Domain Security Management Server. Administrators running any of these versions are advised to review the advisory and apply recommended mitigations.
The advisory details specific hotfix accumulators and takes that contain the fix. For R81.20, the fix is included in Jumbo Hotfix Accumulator Take 161 or later. For R82, the fix is in Take 122 or later, and for R82.10, it is in Take 40 or later. As of the advisory date, no patch is available for earlier versions, and Check Point has not reported active exploitation of the vulnerability.
The Cyber Centre advisory highlights the severity of the issue and urges organizations to assess their exposure. The authentication bypass could potentially allow unauthorized access to management interfaces, which are critical for controlling security policies. Check Point recommends prompt action given the criticality of the affected components.
Organizations using affected versions should prioritize patching, especially if their management servers are exposed to untrusted networks. The advisory and support article provide detailed information on identifying affected installations and applying the necessary fixes. As with any security update, administrators should test the patches in a controlled environment before deploying them to production systems.