CVE-2026-62144
Received Received - Intake

Authentication Bypass in Check Point Security Management

Vulnerability report for CVE-2026-62144, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: Check Point Software Technologies Ltd.

Description

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 22 associated CPEs
Vendor Product Version / Range
check_point security_management *
check_point multi-domain_security_management *
checkpoint security_management r77.30
checkpoint security_management r80
checkpoint security_management r80.10
checkpoint security_management r80.20
checkpoint security_management r80.30
checkpoint security_management r81
checkpoint security_management r81.10
checkpoint security_management r81.20
checkpoint security_management r82
checkpoint security_management r82.10
checkpoint multi-domain_security_management r77.30
checkpoint multi-domain_security_management r80
checkpoint multi-domain_security_management r80.10
checkpoint multi-domain_security_management r80.20
checkpoint multi-domain_security_management r80.30
checkpoint multi-domain_security_management r81
checkpoint multi-domain_security_management r81.10
checkpoint multi-domain_security_management r81.20
checkpoint multi-domain_security_management r82
checkpoint multi-domain_security_management r82.10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-62144 is an authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management products. It allows unauthenticated remote attackers to execute administrative commands on the Management Server. Successful exploitation may also enable command execution on managed Security Gateways.

Detection Guidance

Check for unauthorized administrative access or command execution attempts on Check Point Security Management or Multi-Domain Security Management servers. Review logs for suspicious activity from untrusted IP addresses. Ensure Trusted Clients are restricted to specific IPs or subnets.

Impact Analysis

This vulnerability allows attackers to gain full administrative control over the management system and potentially execute commands on Security Gateways. This could lead to unauthorized access, data breaches, or complete system compromise if the management server is exposed without proper firewall protection.

Compliance Impact

This vulnerability could significantly impact compliance with GDPR and HIPAA by allowing unauthorized administrative access to systems handling sensitive data. Unauthenticated command execution on management servers and firewalls may lead to data breaches, unauthorized data access, or manipulation, violating confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Restrict Trusted Clients to trusted IP addresses or subnets via SmartConsole. Avoid using 'Any' as a Trusted Client type. Enable firewall protection for management access and apply specific Jumbo Hotfix Accumulators: Take 36 for R82.10, Take 118 for R82, and Take 158 for R81.20.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62144. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart