Vulnerability Intelligence Report
Management Authentication Bypass and Privilege Escalation
CVE-2026-62144
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.
Authentication Bypass
No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:3.9
Impact Score:5.2
EPSS Probability:1.01%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-287 ↗CWE-287: Improper Authentication.
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| checkpoint | Quantum Security Management | R82.10 with Jumbo Hotfix Take 36 or below (affected), R82 with Jumbo Hotfix Take 118 or below (affected), R81.20 with Jumbo Hotfix Take 158 or below (affected), R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30 (affected) |
| checkpoint | Multi-Domain Security Management | R82.10 with Jumbo Hotfix Take 36 or below (affected), R82 with Jumbo Hotfix Take 118 or below (affected), R81.20 with Jumbo Hotfix Take 158 or below (affected), R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Check Point Software Ltd. · Vendor · Israel |
| Reserved | 2026-07-13T10:24:07 |
| Published | 2026-07-22T13:53:35 |
| Last Updated | 2026-07-24T03:56:14 |
Community Chatter & Buzz