Panama CSIRT Warns on Check Point CVE-2026-18574
CSIRT Panama and Check Point warned about CVE-2026-18574, a critical flaw that can bypass authentication and run commands.
CSIRT Panama issued an advisory on CVE-2026-18574 in Check Point Security Management Server and Multi-Domain Security Management Server, a critical flaw that can bypass management authentication and execute arbitrary commands. At the time of disclosure, there were no signs of active exploitation, according to the agency and the vendor.
CSIRT Panama published an advisory on the critical vulnerability CVE-2026-18574 in Check Point Security Management Server and Multi-Domain Security Management Server. The agency said there were no signs of active exploitation at the time of disclosure. Check Point said the same in its own advisory and described the issue as a management authentication bypass in those products.
What does CVE-2026-18574 allow?
The vulnerability allows an attacker to bypass management authentication and execute arbitrary commands on the affected system, according to CSIRT Panama. Check Point also said there were no signs of active exploits when it published its bulletin.
What did other CERTs say about CVE-2026-18574?
INCIBE-CERT issued an early warning about CVE-2026-18574 on August 3, describing it as a critical authentication vulnerability in Check Point Security Management Server and MDS that could allow remote execution of arbitrary commands. In that notice, the Spanish agency also said Check Point had no evidence of active exploitation.
Two days later, INCIBE-CERT expanded its coverage with an early warning about three critical vulnerabilities in VMware products. The agency said the impact included VMware ESX, vCenter, Workstation and Fusion, among other related platforms, and recommended applying VMware's patches from bulletin VMSA-2026-0006 immediately.
Outside Latin America, Moneycontrol reported that CERT-In issued a high-severity note on CVE-2026-18574 and stressed the need to install Check Point's security updates. That report widened the case's coverage beyond the region.
Sources
- CVE-2026-18574 | INCIBE-CERTincibe.es· INCIBE-CERT
- Avisos | INCIBE-CERTincibe.es· INCIBE-CERT
- Vulnerabilidad Crítica en Check Point – CVE-2026-18574cert.pa· CSIRT Panamá
- sk185222 - CVE-2026-18574support.checkpoint.com· Check Point
- Check Point Security Management Server vulnerability flagged by CERT-In: What users need to knowmoneycontrol.com· Moneycontrol



