Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-62144: Check Point Management Server Allows Unauthorized Admin Access
CVE-2026-62144
CVE-2026-62144
Summary
An attacker can bypass authentication and gain full access to the Check Point Management Server, potentially executing commands on managed devices. This can happen if the server is not properly protected by a firewall or if the network settings are misconfigured. To fix this, ensure the Management Server is behind a firewall and configure network settings to restrict access to trusted clients only.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| checkpoint | quantum security management | R82.10 with Jumbo Hotfix Take 36 or below |
| checkpoint | multi-domain security management | R82.10 with Jumbo Hotfix Take 36 or below |
Original title
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Ma...
Original description
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.
Vulnerability type
CWE-287
Improper Authentication
Published: 22 Jul 2026 · Updated: 23 Jul 2026 · First seen: 22 Jul 2026