ZeroHour

CVE-2026-62144

large

Authentication Bypass in Check Point Security and Multi-Domain Security Management

CVSS 3.1
9.1 critical
EPSS
21%p97
Published
()
Modified
AI analysis

CVE-2026-62144 is an authentication bypass (CWE-287) in Check Point Security Management and Multi-Domain Security Management that lets an unauthenticated remote attacker execute administrative commands on the Management Server. It is triggered when an attacker can reach the Management Server over the network without firewall protection, or when the management configuration does not restrict Trusted Clients. Successful exploitation gives the attacker full administrative command execution on the management server and may also allow command execution on the managed Security Gateways behind it. Any organization running these Check Point management products where the management interface is reachable without Trusted Clients restriction is affected. As of now there is no public proof-of-concept, it is not in CISA KEV, and no confirmed in-the-wild exploitation is known, although its EPSS of 20.8% (97th percentile) indicates an elevated likelihood of exploitation within 30 days.

What to do: Upgrade Security Management and Multi-Domain Security Management to the patched release per Check Point's official advisory. As interim mitigation, restrict Trusted Clients on the management server and firewall network access to management interfaces, and audit existing configurations for missing Trusted Clients restrictions. Separately, ensure the actively exploited SmartConsole authentication bypass (CVE-2026-16232) is also patched, since it affects the same management ecosystem.

Affected
Check Point Security Management
Check Point Multi-Domain Security Management
Estimated exposure
largetens of thousands of management server deployments, of which only the subset with management interfaces reachable without Trusted Clients restriction are… — Check Point is a leading enterprise firewall vendor whose Security Management/Multi-Domain Management servers are commonly deployed per enterprise or per site (plausibly in the 10k-100k range), but the flaw is only exploitable where…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.

Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news