24 July 2026
Reference: CVE-2026-62144
1. What is being reported?
The vulnerability allows someone without any login credentials to access the Check Point Security Management Server and run administrative commands remotely. This means they could change security settings or even control connected security devices. The problem happens if the Management Server is accessible on the network without strong firewall protection or restrictions on trusted clients.
2. What this means in plain English
If exploited, this flaw could let attackers gain full control over your network’s security management, potentially disabling protections or opening doors for further attacks. For a small organisation, this could mean loss of data, disruption of services, or exposure to other cyber threats.
3. Could this affect a small business?
Small businesses using Check Point Security Management or Multi-Domain Security Management software could be affected, especially if their Management Server is accessible from outside their secure network or lacks proper firewall rules. Organisations not using this software or those with strong network protections are less likely to be impacted.
4. What to do now
- Contact your IT provider immediately to check if you use Check Point Security Management software.
- Ensure your Management Server is not directly accessible from the internet or untrusted networks.
- Verify that firewall rules restrict access to the Management Server only to trusted devices.
- Ask your IT provider or Check Point for available patches or updates to fix this vulnerability.
5. Ask your IT provider
Do we use Check Point Security Management software, and if so, is our Management Server protected against the CVE-2026-62144 authentication bypass vulnerability?
6. Bottom line
If you use Check Point’s management software, act quickly to secure it and prevent attackers from taking control of your network security.
Information based on CISA KEV, NVD and reputable security reporting.