CVE-2026-62144
Management Authentication Bypass and Privilege Escalation
Description
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.
In plain language
AI Act nowCVE-2026-62144 is an internet-facing flaw in Check Point “quantum security management” and “Multi-Domain Security Management” where attackers can bypass login and run admin commands; if your Management Server is reachable from the internet, a typical small business should treat this as an emergency.
Unauthenticated remote authentication bypass (CWE-287) in Check Point quantum security management / Multi-Domain Security Management allows remote command execution with administrative privileges when the Management Server is reachable and Trusted Client access is not properly restricted.
What to do now
- Check whether your Check Point quantum security management / Multi-Domain Security Management Management Server is reachable from the internet (e.g., public IP exposure, no firewall allowlist).
- Verify your “Trusted Client” configuration is restricted (only approved client IPs/accounts allowed) and that unauthenticated remote access is blocked.
- Immediately restrict network access to the Management Server to approved management hosts only (tight firewall rules, block all other inbound internet traffic).
- Apply the vendor’s recommended mitigations as soon as they’re released, and actively hunt for signs of admin-command activity from unknown sources.
- Escalate to your IT/security vendor with CVE-2026-62144 and request an official fixed version timeline, since no patch information is available in our sources.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wilden·Rapid7 Blog· Exploited Security Management auth-bypass
- Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)en-us·Help Net Security· Exploited Check Point Security Management auth-bypass
- New Check Point Zero-Day Vulnerability Exploited in the Wilden-us·SecurityWeek· Exploited Security Management zero-day
- Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Accessen·The Hacker News· Exploited SmartConsole zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62144 and every CVE in our database. Create a free account — no credit card required.
Create Free Account