Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-62144: Check Point Management Server Allows Unauthorized Admin Access

CVE-2026-62144 CVE-2026-62144
Summary

An attacker can bypass authentication and gain full access to the Check Point Management Server, potentially executing commands on managed devices. This can happen if the server is not properly protected by a firewall or if the network settings are misconfigured. To fix this, ensure the Management Server is behind a firewall and configure network settings to restrict access to trusted clients only.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
checkpoint quantum security management R82.10 with Jumbo Hotfix Take 36 or below
checkpoint multi-domain security management R82.10 with Jumbo Hotfix Take 36 or below
Original title
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Ma...
Original description
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.
Vulnerability type
CWE-287 Improper Authentication
Published: 22 Jul 2026 · Updated: 23 Jul 2026 · First seen: 22 Jul 2026