Checkpoint security advisory (AV26-774)
Serial Number: AV26-774 Date: August 3, 2026 As of August 3, 2026, checkpoint is affected by a vulnerability in the following products: Multi-Domain Security Management Server (MDS) R80 R80.10 R80.20 R80.30 R80.40 R81 R81.10 R81.20 with Jumbo Hotfix Accumulator Take 160 or below R82 with Jumbo Hotfix Accumulator Take 121 or below R82.10 with Jumbo Hotfix Accumulator Take 39 or below Security Management Server R80 R80.10 R80.20 R80.30 R80.40 R81 R81.10 R81.20 with Jumbo Hotfix Accumulator Take 160 or below R82 with Jumbo Hotfix Accumulator Take 121 or below R82.10 with Jumbo Hotfix Accumulator Take 39 or below The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. sk185222 - CVE-2026-18574 - Management Authentication Bypass Check Point Security
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/checkpoint-security-advisory-av26-774
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-185740.99% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 59% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18574 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEU] [hoch] Check Point Security Management: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und…cert-bund
- unknownVulnérabilité dans les produits Check Point (04 août 2026)cert-fr-avis
- unknownCVE-2026-18574: An authentication bypass vulnerability in Check Point Security Management Server and Multi-Dom…nvd
More from Canadian Centre for Cyber Security
- unknownVeeam security advisory (AV26-777)2026-08-04
- unknownAdobe security advisory (AV26-776)2026-08-04
- unknownN-able security advisory (AV26-769) - Update 12026-08-04
- unknownMISP security advisory (AV26-775)2026-08-04
- unknownTenable, Inc. security advisory (AV26-773)2026-08-04