← Back to blog Cybersecurity

Critical Check Point Management flaw allows root code execution without a password: what to check today on the firewall of your Mexico operation

4 min read

On September 17, 2026, Check Point disclosed a critical flaw in its management server (Security Management and Multi-Domain) that lets someone with no username or password run code as root. Root is the account that owns the whole system. The Hacker News broke the story and BleepingComputer followed the next day.

Why does it matter so much? Because that server is where every firewall rule lives. Whoever controls the console does not break one firewall: they rewrite all of them. And in our experience, in many Mexico sites of foreign companies that console is reachable from any PC on the local network, sometimes from the internet, and often nobody in Mexico knows who owns it.

What actually broke, in plain language

Gateway and console are not the same The gateway filters traffic at the plant or branch. Security Management is where the rules are drawn. The flaw is in the second one.

A typical Check Point deployment has two pieces. Quantum gateways are the boxes filtering traffic at the plant in Querétaro or the warehouse in Monterrey. Security Management is the server where your network team draws the rules with SmartConsole, usually at headquarters. Multi-Domain is the large version, for corporates that manage several countries from one place.

The flaw lives in that management server. As of this writing there is no confirmed exploitation, but the patch is out. That is the best moment to act: later it becomes a race.

How to find your version and hotfix

First the number, then the patch Without the version and installed hotfix you cannot know whether you are covered. It takes two minutes.

Three ways, from easiest to most exact:

Where to lookWhat it tells you
SmartConsole, Help menu, AboutManagement and client version
Gaia web portal (the operating system of the appliance)Version and latest Jumbo Hotfix installed
Server console, expert modeFull list of hotfixes

From the console, this command lists everything installed:

cpinfo -y all

Write down the version and hotfix number, then compare against the official advisory linked in the sources above. If headquarters runs the console, ask them for that number today. If a local partner runs it, ask them too. If nobody answers, you just found the real problem.

Where to get the patch and how to apply it

The fix downloads from the Check Point Support Center with your User Center account and installs through CPUSE, the package installer built into Gaia. If you have an active support contract, your partner can push it for you.

Lock the console to an admin network

Management only over VPN The console should be reachable from two or three machines, not from the whole network or the internet.

This is the change that protects the most, and the one almost nobody makes. Check Point lets you define which addresses can manage it: SmartConsole has a Trusted Clients list and Gaia has an allowed hosts list. Keep it to the admin workstations at headquarters and an administrators VPN. Nothing else.

If the management ports are published to the internet today so the local vendor can connect from home, close them and give that vendor a VPN account. Same advice we gave for the Cisco ISE zero-day: management never gets exposed.

What to look for in logs and admin accounts

Thirty days back Who published policies, from where, and which admin accounts appeared without anyone asking for them.

Even without confirmed exploitation, review the last thirty days:

  • Audit logs in SmartConsole: who published policies, when and from which address.
  • Administrator list: new accounts, superuser accounts nobody remembers creating, the old partner that still has access.
  • Rule changes outside business hours, especially new allow-anything rules toward servers.
  • Management sessions from addresses that are not your people, in either country.

A firewall with no owner is worse than an old one

Our honest opinion: in the Mexico sites we visit, the problem is almost never the hardware. The firewall was installed by an integrator four years ago, headquarters assumes Mexico watches it, Mexico assumes headquarters does, and nobody reads the advisories. An old appliance with patches and an attentive owner holds up. A new one with no owner is an open door with the lights on.

At ProcessBi firewall review and patching is part of the support plan. If your Mexico site has no network team, we manage the perimeter for you and report to headquarters in English. And if you only want to know where you stand, we run an express audit of console access.

ProcessBi engineer reviewing a client firewall in Mexico
Tell us your version and we will tell you if you are covered Foto: Pexels

And in your Mexico operation?

If nobody can tell you today who holds the Check Point password for the Mexico site, that is the first item. The version is the second. Locking down the console is the third.

Book your free assessment — we reply the same business day.

Your path

Running IT in Mexico from abroad

30 of 32
  1. Smart hands ✓ Read You are here 2 min
  2. Remote support ✓ Read You are here 3 min
  3. Nearshoring checklist ✓ Read You are here 2 min
  4. Retail rollouts ✓ Read You are here 2 min
  5. Fake IT support ✓ Read You are here 3 min
  6. Backups that restore ✓ Read You are here 3 min
  7. Secure M365 ✓ Read You are here 3 min
  8. Windows 10 deadline ✓ Read You are here 4 min
  9. Audit app access ✓ Read You are here 3 min
  10. CEO fraud ✓ Read You are here 4 min
  11. Office 2016 cutoff ✓ Read You are here 3 min
  12. Patch today ✓ Read You are here 4 min
  13. Patch VMware ✓ Read You are here 4 min
  14. Office 2021 EOL ✓ Read You are here 3 min
  15. Starlink for sites ✓ Read You are here 3 min
  16. Cardless access ✓ Read You are here 4 min
  17. Control AI on PCs ✓ Read You are here 4 min
  18. ScreenConnect flaw ✓ Read You are here 4 min
  19. Server 2022 EOL ✓ Read You are here 3 min
  20. Exposed cameras ✓ Read You are here 3 min
  21. Domain trust fix ✓ Read You are here 4 min
  22. Patch Cisco ISE ✓ Read You are here 3 min
  23. Protect the plant ✓ Read You are here 3 min
  24. Move to 25H2 ✓ Read You are here 4 min
  25. Outages and UPS ✓ Read You are here 3 min
  26. IT maintenance ✓ Read You are here 4 min
  27. Third-party scripts ✓ Read You are here 3 min
  28. License audit ✓ Read You are here 4 min
  29. Bajío fiber corridor ✓ Read You are here 3 min
  30. Check Point flaw ✓ Read You are here 4 min
  31. Cashless payments ✓ Read You are here 3 min
  32. AI that hacks alone ✓ Read You are here 3 min
  33. Field services
Next Mexico's Digital Economy Law and the move away from cash: the IT your Mexico operation needs to take digital payments without breaking