Executive brief
Check Point SmartConsole is a management application used to configure and monitor corporate network security policies. A critical vulnerability allows an unauthorized person to bypass the login process and gain full administrative control over the security infrastructure. This could allow an attacker to disable firewalls, change security rules, or gain access to sensitive internal network traffic. Check Point has confirmed that this flaw is currently being exploited in the wild.
Technical details
An authentication bypass vulnerability (CWE-287) exists in the Check Point SmartConsole login process. The flaw allows a remote, unauthenticated attacker to intercept or generate a valid application login token. With this token, the attacker can authenticate to the Management Server with full administrative privileges. Exploitation requires the Management Server's IP to be reachable over the network and a configuration that does not restrict 'Trusted Clients.' Check Point reports active exploitation of this vulnerability. Users should apply the latest Jumbo Hotfix Accumulator for their respective versions (R82.10, R82, R81.20, etc.) to mitigate the risk.
Affected products
- Check Point Quantum Security Management R82.10 Take 36 and below; R82 Take 118 and below; R81.20 Take 158 and below; R81.10, R81, R80.x, R77.30
- Check Point Multi-Domain Security Management R82.10 Take 36 and below; R82 Take 118 and below; R81.20 Take 158 and below; R81.10, R81, R80.x, R77.30
- Check Point SmartConsole All versions used with affected Management Servers
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory
- 2026-07-22: exploited: Confirmed active exploitation in the wild at time of disclosure.