Search/CVE-2026-18574
CVE

CVE-2026-18574

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation.

CVSS v3.1
EPSS
0.99%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
1
sources referencing this CVE
Connections
3 relationships
Timeline
disclosure → media coverage
Aug 3, 2026
Disclosure — published as a CVE record.
Sep 17, 2026
thehackernews.com reports: Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
Public PoC (1)
Unverified third-party code — review before executing.