Affected Systems

Check Point Security Management Server and Multi-Domain Security Management Server (MDS) SmartConsole. All versions prior to Jumbo Hotfixes released July 22, 2026. Exploitation requires network access to Management Server and configurations without Trusted Client restrictions.

Exploitation Status

Active exploitation confirmed in the wild as a zero-day. Check Point reports a handful of customers targeted. Public proof-of-concept Python script released by Rapid7 on July 29, 2026.

Business Impact

Unauthenticated remote attackers can obtain full administrative access to Check Point management infrastructure, allowing complete modification of security policies and configurations across managed firewalls. This enables attackers to disable protections, create backdoor rules, exfiltrate configuration data, or disrupt security operations. Organizations using Check Point centralized management are at immediate risk of complete security posture compromise.

Urgency

🔴 Immediate

Recommended Actions

  • Apply Check Point Jumbo Hotfixes released July 22, 2026, immediately to all Security Management Servers and Multi-Domain Security Management Servers
  • Restrict network access to Management Servers using Trusted Clients configuration to limit attack surface until patching is complete
  • Review SmartConsole authentication logs for suspicious application login token requests or SSO ticket generation from unexpected sources since initial exploitation window
  • Use Rapid7's published PoC Python script to validate patch status across all management servers in your environment
  • Audit security policy changes made in the past 30-60 days for unauthorized modifications that may indicate prior compromise