Record summary

CVE-2026-18574 has a selected CVSS score of 9.3 (critical).

Description

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 4, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListR82.10 with Jumbo Hotfix Accumulator Take 39 or belowaffected
R82 with Jumbo Hotfix Accumulator Take 121 or belowaffected
R81.20 with Jumbo Hotfix Accumulator Take 160 or belowaffected
R81.10affected
R81affected
R80.40affected
R80.30affected
R80.20affected
R80.10affected
R80affected
CVE ListR82.10 with Jumbo Hotfix Accumulator Take 39 or belowaffected
R82 with Jumbo Hotfix Accumulator Take 121 or belowaffected
R81.20 with Jumbo Hotfix Accumulator Take 160 or belowaffected
R81.10affected
R81affected
R80.40affected
R80.30affected
R80.20affected
R80.10affected
R80affected

Research & analysis

1
X research thread@threadlinqsSource: EIP research review

CVE-2026-18574 SIC DN replay root cause

Check Point advisory sk185222 discloses a critical authentication bypass (CVE-2026-18574) in Security Management Server and Multi-Domain Security Management Server. An unauthenticated remote attacker with network access to Management services can bypass authentication and execute arbitrary commands, potentially resulting in full compromise of the Security Management system. The root cause, identified by external researcher @threadlinqs, is SIC (Secure Internal Communication) DN replay. The vulnerability was discovered internally by Check Point with no indication of active exploitation at disclosure. Affected supported versions include R81.20, R82, and R82.10, plus EoS branches R80 through R81.10. Fixes are available via Jumbo Hotfix Accumulator takes. Smart-1 Cloud customers are already protected. The advisory provides hardening guidance including Trusted Client restriction and management access controls as interim mitigations.

Root causeTechnical detailMitigationContext
https://x.com/threadlinqs/status/2084518243071410390
Research notes

References

1