Check Point Product Security Update Advisory
Overview
A security update has been released to address several vulnerabilities in Check Point products. The affected products are Security Management Server, Multi-Domain Security Management Server (MDS), Security Gateway, Check Point Spark Firewall, Log Server, and Multi-Domain Log Server.
Resolved Vulnerabilities
- CVE-2026-18574: An arbitrary command execution vulnerability caused by administrative authentication bypass in the Security Management Server and Multi-Domain Security Management Server.
- CVE-2026-62144: A vulnerability in the Security Management Server and Multi-Domain Security Management Server (MDS) that allows for administrative authentication bypass and privilege escalation.
- CVE-2026-85102: A vulnerability in the Security Gateway and Spark Firewall that allows authentication bypass and remote code execution.
- CVE-2026-85103: A vulnerability in the Security Gateway, Security Management Server, and Spark Firewall that allows remote code execution.
- CVE-2026-91843: A remote code execution vulnerability with root privileges caused by a stack overflow (memory handling error) in Security Management and Log Server.
Patch Information
Vulnerability Patches have been provided via the latest updates. The applicable versions for each product are as follows:
- CVE-2026-18574: R81.20 Jumbo Hotfix Accumulator Take 161 or higher, R82 Jumbo Hotfix Accumulator Take 122 or higher, R82.10 Jumbo Hotfix Accumulator Take 40 or higher.
- CVE-2026-62144: R81.20 Jumbo Hotfix Accumulator Take 158 or higher, R82 Jumbo Hotfix Accumulator Take 118 or higher, R82.10 Jumbo Hotfix Accumulator Take 36 or higher.
- CVE-2026-85102, CVE-2026-85103: R81.10 Jumbo Hotfix Accumulator Take 190 or higher, R81.20 Jumbo Hotfix Accumulator Take 166 or higher, R82 Jumbo Hotfix Accumulator Take 126 or higher, R82.10 Jumbo Hotfix Accumulator Take 44 or higher, Check Point Spark Firewall R81.10.17 Build 4968 or higher, Check Point Spark Firewall R82.00.10 Build 2325 or higher.
- CVE-2026-91843: R81.20 Check Point LivePatch Take 28 or later, R82 Check Point LivePatch Take 28 or later, R82.10 Check Point LivePatch Take 28 or later, R82.20 Check Point LivePatch Take 29 or later.
Note
Users of these products must update to the latest version with Vulnerability Patches according to the instructions on the reference site.