Panama CSIRT Warns on Check Point CVE-2026-18574
CSIRT Panama and Check Point warned about CVE-2026-18574, a critical flaw that can bypass authentication and run commands.
CSIRT Panama issued an advisory on CVE-2026-18574 in Check Point Security Management Server and Multi-Domain Security Management Server, a critical flaw that can bypass management authentication and execute arbitrary commands. At the time of disclosure, there were no signs of active exploitation, according to the agency and the vendor.
Alert on Check Point
CSIRT Panama published an advisory on the critical vulnerability CVE-2026-18574 in Check Point Security Management Server and Multi-Domain Security Management Server. According to the agency, there were no signs of active exploitation at the time of disclosure. Check Point said the same in its own advisory and described the issue as a management authentication bypass in those products.
The vulnerability allows attackers to bypass management authentication and execute arbitrary commands on affected systems, according to CSIRT Panama. Check Point also said there were no signs of active exploits at the time it published its bulletin.
Response from other CERTs
INCIBE-CERT issued an early warning about CVE-2026-18574 on Aug. 3, describing it as a critical authentication vulnerability in Check Point Security Management Server and MDS that could allow remote execution of arbitrary commands. In that notice, the Spanish agency also said Check Point had no signs of active exploitation.
Two days later, INCIBE-CERT expanded its coverage with an early warning on three critical vulnerabilities in VMware products. The agency said VMware ESX, vCenter, Workstation and Fusion, among other associated platforms, were affected and recommended applying the patches VMware released in bulletin VMSA-2026-0006 immediately.
Outside Latin America, Moneycontrol reported that CERT-In issued a high-severity notice on CVE-2026-18574 and stressed the need to install Check Point security updates. That report broadened the case's coverage beyond the region.
Sources
- CVE-2026-18574 | INCIBE-CERTincibe.es· INCIBE-CERT
- Avisos | INCIBE-CERTincibe.es· INCIBE-CERT
- Vulnerabilidad Crítica en Check Point – CVE-2026-18574cert.pa· CSIRT Panamá
- sk185222 - CVE-2026-18574support.checkpoint.com· Check Point
- Check Point Security Management Server vulnerability flagged by CERT-In: What users need to knowmoneycontrol.com· Moneycontrol



