Check Point fixed a flaw that allowed bypassing authentication on its Security Management and Multi-Domain Security Management servers. This issue is tracked as CVE-2026-18574 and has a CVSS score of 9.3. Check Point discovered the problem themselves and says there are no current attacks.
Why it matters
By infosecbulletin
/ Monday , August 24 2026
A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
By infosecbulletin
/ Monday , August 24 2026
A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
By infosecbulletin
/ Sunday , August 23 2026
More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
By infosecbulletin
/ Sunday , August 23 2026
US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
By infosecbulletin
/ Friday , August 21 2026
Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
By infosecbulletin
/ Friday , August 21 2026
T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
By infosecbulletin
/ Friday , August 21 2026
Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
By infosecbulletin
/ Friday , August 21 2026
Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
By infosecbulletin
/ Thursday , August 20 2026
CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
By infosecbulletin
/ Thursday , August 20 2026
Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days...
Read More
An attacker without permission can use this flaw to run any commands on the Security Management Server. Check Point warns that if this is exploited, the entire Security Management system could be at risk. This system is very important because it manages rules for all connected gateways.
A compromised Management Server could allow an attacker to change firewall rules, change admin permissions, or turn off logging for the whole system. Check Point has fixed similar issues with Management-tier security in the past, some of which were later used by attackers. This history shows that quick patches are important, even if there’s no known attack this time.
How the attack works
Exploitation needs access to the Security Management Server. Check Point warns that systems allowing Management services on untrusted networks or not limiting Trusted Clients are at higher risk of Check Point authentication bypass.
Exploitation status
Check Point clearly says that they found this issue on their own and there are no signs of any active attacks at this time.
Affected versions and patch
The affects affects R80 to R81.10, which are no longer supported, as well as the currently supported R81.20, R82, and R82.10. Smart-1 Cloud users are already safe. Updates are sent in the Jumbo Hotfix Accumulator for each supported version. Admins should read the full advisory, apply the hotfix, and limit Trusted Clients to approved hosts for now.

Copilot reads ‘confidential emails’ bypassing DLP policies