CVE-2026-18574 SIC DN replay root cause
Check Point advisory sk185222 discloses a critical authentication bypass (CVE-2026-18574) in Security Management Server and Multi-Domain Security Management Server. An unauthenticated remote attacker with network access to Management services can bypass authentication and execute arbitrary commands, potentially resulting in full compromise of the Security Management system. The root cause, identified by external researcher @threadlinqs, is SIC (Secure Internal Communication) DN replay. The vulnerability was discovered internally by Check Point with no indication of active exploitation at disclosure. Affected supported versions include R81.20, R82, and R82.10, plus EoS branches R80 through R81.10. Fixes are available via Jumbo Hotfix Accumulator takes. Smart-1 Cloud customers are already protected. The advisory provides hardening guidance including Trusted Client restriction and management access controls as interim mitigations.
Research notes
- Root causeThe vulnerability is an authentication bypass via SIC (Secure Internal Communication) DN replay in Check Point Security Management.
- Technical detailSuccessful exploitation requires network access to the Security Management Server. Environments that do not restrict Trusted Clients (GUI clients) or that expose Management services to untrusted networks may have increased exposure.
- MitigationFixed in Jumbo Hotfix Accumulator for R82.10 starting from Take 40, R82 starting from Take 122, and R81.20 starting from Take 161. Smart-1 Cloud customers are already protected.
- ContextThe vulnerability was discovered internally by Check Point with no indication of active exploitation at the time of disclosure.