Rapid7 released a public proof-of-concept script for a critical authentication bypass vulnerability in Check Point SmartConsole that allows unauthenticated attackers to gain administrative privileges.

Reader brief
Through the Reader lens: Security firm Rapid7 has published a working proof-of-concept script for a critical flaw (CVSS 9.3) in Check Point's SmartConsole that lets unauthenticated attackers bypass authentication and take administrative control — and exploitation is already known. The disclosure lands amid a cluster of other critical Check Point bugs: two VPN certificate vulnerabilities that could enable unauthenticated remote code execution, and a stack overflow in Security Management and Log Servers allowing unauthenticated attackers to run code as root. Any organization running Check Point management infrastructure — versions from R81.10 through R82.20 — is potentially exposed. Check Point released Jumbo Hotfixes on July 22, 2026, and no workaround is listed, so patching is the only real defense. Coverage across security outlets is factual and neutral with no vendor dispute; the open question is how quickly exploitation scales now that attack code is public. Watch for scanning waves against management interfaces and any CISA KEV listing.
What to watch next
- Patch all Check Point management servers with the July 22 hotfixes
- Confirm SmartConsole admin access is restricted to trusted hosts
- Monitor for exploitation attempts against management interfaces
- Watch for CISA KEV listing and mass exploitation reports
What was said2
Attributed, verbatim. Every quote is checked against the article it came from. One that does not match is not shown.
Aviv Abramovich
1 quote“only through trusted clients”
In the article
…Settings, Permissions & Administrators, Trusted Clients, according to the hardening guide, which also says that direct internet access to management should be avoided and that a VPN is required. The vulnerable path is " only through trusted clients ," Abramovich said, and Check Point recommends that customers verify the setting is not set to any IP address but to trusted hosts. Censys said it observes 3,836 hosts worldwide that present the default identity Check…
Check Point
1 quote“At this time, there is no indication that this vulnerability has been exploited in the wild,”
In the article
…enabled are already protected, and that everyone else should apply the LivePatch fix described in advisory sk1000155. It urged customers to take immediate action because of the flaw's severity and potential impact. " At this time, there is no indication that this vulnerability has been exploited in the wild, " the notice said. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recorded exploitation as "none" in its assessment attached to the CVE record on September 17. The flaw was not in CISA's Known…
So what7
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Organizations running Check Point SmartConsole administrative access bypass· immediate
- Check Point Security Management and Log Server operators unauthenticated root rce· immediate
- Check Point VPN deployments remote code execution· immediate
- Check Point (vendor) emergency patch release· days
- Organizations using affected Check Point products patch required· days
- Network-exposed Check Point management interfaces increased exploitation attempts· days
- Downstream Check Point gateways and policies gateway policy tampering· weeks
Sources3
- [1]The Hacker NewsneutralCritical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
- [2]The Hacker NewsneutralCheck Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
- [3]The Hacker NewsneutralPublic PoC Released for Exploited Check Point SmartConsole Authentication Bypass