Check Point has issued a high-severity security alert for CVE-2026-18574, a management authentication-bypass flaw that can allow an unauthenticated attacker to execute arbitrary commands on vulnerable Security Management Server and Multi-Domain Security Management Server deployments This article explores trusted clients smartconsole. . The vulnerability is tracked under Solution ID sk185222, creating a direct path for full compromise of the security-management plane where attackers could alter policies, administer managed gateways, and harvest sensitive configuration data.

Critical Check Point Flaw Exploitation necessitates network access to the target management server, making internet-exposed administration services or permissive internal management networks the primary risk scenarios. Organizations that permit unrestricted GUI client connections or expose management interfaces to untrusted networks face heightened exposure during routine administrative operations and remote access.

The company recommends administrators immediately apply its management-hardening guidance while deployment teams schedule relevant Jumbo Hotfix Accumulator updates. The first priority is to restrict Trusted Clients in SmartConsole, under Manage & Settings, Permissions & Administrators, where administrators should edit each entry to limit access to explicitly authorized hosts and subnets. Given the end-of-support status for legacy R80 through R81.10 releases, organizations should prioritize migration planning over relying on compensating controls alone.