Full Report
Checkpoint security advisory (AV26-774)
Analysis Summary
# Vulnerability: Check Point Management Authentication Bypass
## CVE Details
- **CVE ID:** CVE-2026-18574
- **CVSS Score:** 9.8 (Critical) - *Estimated based on standard Authentication Bypass impact*
- **CWE:** CWE-287 (Improper Authentication)
## Affected Systems
- **Products:** Multi-Domain Security Management Server (MDS) and Security Management Server
- **Versions:**
- R80, R80.10, R80.20, R80.30, R80.40
- R81, R81.10
- R81.20: Jumbo Hotfix Accumulator Take 160 or below
- R82: Jumbo Hotfix Accumulator Take 121 or below
- R82.10: Jumbo Hotfix Accumulator Take 39 or below
- **Configurations:** Systems running affected versions of management software exposed to network access.
## Vulnerability Description
CVE-2026-18574 is a critical authentication bypass vulnerability affecting Check Point Security Management and Multi-Domain Management servers. The flaw allows a remote, unauthenticated attacker to bypass the authentication process and gain unauthorized access to the management server. This occurs due to improper validation within the management authentication component, potentially granting the attacker administrative privileges over the security infrastructure.
## Exploitation
- **Status:** Not explicitly stated as "exploited in the wild" in the provided text, but high-priority advisory suggests imminent risk.
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High (Full access to security policies, logs, and credentials)
- **Integrity:** High (Ability to modify security rules and management configurations)
- **Availability:** High (Potential to lock out legitimate admins or shut down management services)
## Remediation
### Patches
Check Point has released fixes via Jumbo Hotfix Accumulators. Users should upgrade to the following or higher:
- **R81.20:** Install Jumbo Hotfix Accumulator Take 161 or higher.
- **R82:** Install Jumbo Hotfix Accumulator Take 122 or higher.
- **R82.10:** Install Jumbo Hotfix Accumulator Take 40 or higher.
- **Legacy Versions (R80.x to R81.10):** These versions are likely end-of-engineering; customers are strongly advised to upgrade to a supported version (R81.20+) and apply the latest Jumbo Hotfix.
### Workarounds
- **Network Isolation:** Ensure Management Servers are not accessible from the public internet.
- **Access Control:** Restrict access to the management interface (GUI and CLI) to specific trusted IP addresses or via a secure VPN/Management network only.
## Detection
- **Indicators of compromise:** Monitor Management logs for unusual login activity from unknown IP addresses or administrative actions (policy changes) not initiated by authorized personnel.
- **Detection methods and tools:** Audit `cp.elg` and `admin_audit.log` for unauthorized sessions or authentication attempts bypassing standard workflows.
## References
- **Vendor advisory:** hxxps[://]support[.]checkpoint[.]com/results/sk/sk185222
- **Check Point Security Blog:** hxxps[://]blog[.]checkpoint[.]com/security/
- **Canadian Centre for Cyber Security:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/checkpoint-security-advisory-av26-774