Check Point Security Management RCE flaw patched
A vulnerability in Check Point Security Management and Multi-Domain Security Management allows remote code execution and security policy bypass.
ANSSI-CERT-FR has published an advisory regarding a vulnerability affecting Check Point's Multi-Domain Security Management and Security Management products across multiple version branches, including R81.20, R82, and R82.10, as well as legacy versions R80 through R81.10. The flaw, tracked as CVE-2026-18574, allows an attacker to bypass security policy controls and achieve remote arbitrary code execution.
Check Point has released patches addressing the issue, detailed in vendor bulletin sk185222 published August 2, 2026. Organizations running affected versions of Check Point management products are advised to apply the corresponding fixes referenced in the vendor documentation. No indication of active exploitation is provided in this advisory.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0965
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free