Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN818
_____________________________________________________________________

DATE                : 04/08/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Multi-Domain Security Management
                      Server (MDS),  Security Management Server.
 
=====================================================================
https://support.checkpoint.com/results/sk/sk185222
_____________________________________________________________________

CVE-2026-18574 - Management Authentication Bypass
Please read this important update from Check Point.

Security Alert:
High

Product
Multi-Domain Security Management, Security Management
VersionR80 (EOS), R80.10 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS),
R81.10 (EOS), R81.20, R82, R82.10

Last Modified
2026-08-03

Symptoms

    Impact: An unauthenticated attacker may be able to bypass Management
authentication and execute arbitrary commands on the Security Management
Server. Successful exploitation could result in full compromise of the
Security Management system.

    This issue was discovered internally, and Check Point has no
indication of active exploits.

    This issue received the ID CVE-2026-18574.

    Affected Products and Versions

    Products: Security Management Server, Multi-Domain Security Management
Server (MDS).
                    Note: Smart-1 Cloud customers are already protected.
    Versions:
        R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10 (all EoS)
        R81.20, R82, R82.10

    Conditions: Successful exploitation requires network access to the
Security Management Server.

    Environments that do not restrict Trusted Clients (GUI clients) or
that expose Management services to untrusted networks may have
increased exposure.


    Mitigation
        Follow the Check Point Hardening Best Practices Guide.

        Restrict Trusted Clients - Limit Trusted Clients (GUI clients)
to authorized IP addresses and networks.
        To configure Trusted Clients:
            In SmartConsole, go to Manage & Settings > Permissions & Administrators > Trusted Clients.
            Double-click the client you want to edit.
            In the Trusted Client configuration window that opens,
restrict access to authorized hosts and subnets only.
            Make sure do not use "Any" as a Trusted Client definition.
            Click OK and install the Security policy.

        Protect Management Access
            Restrict Management access using Firewall policy.
            Allow Management connectivity only from trusted
administrative workstations.
            Make sure implied rules protecting control
connections are enabled.
            Verify that Management services are not
exposed to untrusted networks.

    Implementing the above measures can significantly reduce
exposure until the relevant fix is applied.


Solution

This problem was fixed. The fix is included in:

    Jumbo Hotfix Accumulator for R82.10 starting from Take 40
    Jumbo Hotfix Accumulator for R82 starting from Take 122
    Jumbo Hotfix Accumulator for R81.20 starting from Take 161


Article Properties

Access Level
General

Severity
High

Status
Approved

Date Created
2026-08-01

Last Modified
2026-08-03


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




