Check Point 2026-08-06

Critical Check Point Flaw Lets Unauthenticated Attackers Execute Commands on Management Servers (CVE-2026-18574)

内容摘要

Check Point has disclosed a high-severity authentication bypass vulnerability that could allow unauthenticated attackers to execute arbitrary commands on vulnerable Security Management Servers and Multi-Domain Security Management Servers (MDS). This vulnerability is tracked as CVE-2026-18574 and is detailed in Check Point Security Alert sk185222. It affects multiple legacy and current versions of their management platform. Successful exploitation of this vulnerability could lead to the complete compromise of an organization's Check Point Security Management environment, potentially giving attackers control over centrally managed gateways, policies, configurations, and sensitive security data. According to the vendor, the vulnerability was discovered internally, and there is currently no indication of active exploitation in the wild as of the last update to the alert on August 3, 2026. The issue affects Check Point Security Management Server and Multi-Domain Security Management Server deployments including R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10, R81.20, R82, and R82.10. Most affected R80 versions and early R81 versions have reached end of support. Check Point has indicated that Smart-1 Cloud customers are already protected. Exploitation requires network access to the targeted management server. Environments with management services exposed to untrusted networks, or those that allow overly broad Trusted Client access, are at higher risk. Check Point has resolved this issue through updates included in its Jumbo Hotfix Accumulators.
来源: 快科技
查看原文 →

觉得这篇分析有用?

每周收到3-5条AI基础设施关键信号 →

💬 评论 (0)