Critical Check Point Management flaw allows root code execution without a password: what to check today on the firewall of your Mexico operation
On September 17, 2026, Check Point disclosed a critical flaw in its management server (Security Management and Multi-Domain) that lets someone with no username or password run code as root. Root is the account that owns the whole system. The Hacker News broke the story and BleepingComputer followed the next day.
Why does it matter so much? Because that server is where every firewall rule lives. Whoever controls the console does not break one firewall: they rewrite all of them. And in our experience, in many Mexico sites of foreign companies that console is reachable from any PC on the local network, sometimes from the internet, and often nobody in Mexico knows who owns it.
What actually broke, in plain language
A typical Check Point deployment has two pieces. Quantum gateways are the boxes filtering traffic at the plant in Querétaro or the warehouse in Monterrey. Security Management is the server where your network team draws the rules with SmartConsole, usually at headquarters. Multi-Domain is the large version, for corporates that manage several countries from one place.
The flaw lives in that management server. As of this writing there is no confirmed exploitation, but the patch is out. That is the best moment to act: later it becomes a race.
How to find your version and hotfix
Three ways, from easiest to most exact:
| Where to look | What it tells you |
|---|---|
| SmartConsole, Help menu, About | Management and client version |
| Gaia web portal (the operating system of the appliance) | Version and latest Jumbo Hotfix installed |
| Server console, expert mode | Full list of hotfixes |
From the console, this command lists everything installed:
cpinfo -y all
Write down the version and hotfix number, then compare against the official advisory linked in the sources above. If headquarters runs the console, ask them for that number today. If a local partner runs it, ask them too. If nobody answers, you just found the real problem.
Where to get the patch and how to apply it
The fix downloads from the Check Point Support Center with your User Center account and installs through CPUSE, the package installer built into Gaia. If you have an active support contract, your partner can push it for you.
Lock the console to an admin network
This is the change that protects the most, and the one almost nobody makes. Check Point lets you define which addresses can manage it: SmartConsole has a Trusted Clients list and Gaia has an allowed hosts list. Keep it to the admin workstations at headquarters and an administrators VPN. Nothing else.
If the management ports are published to the internet today so the local vendor can connect from home, close them and give that vendor a VPN account. Same advice we gave for the Cisco ISE zero-day: management never gets exposed.
What to look for in logs and admin accounts
Even without confirmed exploitation, review the last thirty days:
- Audit logs in SmartConsole: who published policies, when and from which address.
- Administrator list: new accounts, superuser accounts nobody remembers creating, the old partner that still has access.
- Rule changes outside business hours, especially new allow-anything rules toward servers.
- Management sessions from addresses that are not your people, in either country.
A firewall with no owner is worse than an old one
Our honest opinion: in the Mexico sites we visit, the problem is almost never the hardware. The firewall was installed by an integrator four years ago, headquarters assumes Mexico watches it, Mexico assumes headquarters does, and nobody reads the advisories. An old appliance with patches and an attentive owner holds up. A new one with no owner is an open door with the lights on.
At ProcessBi firewall review and patching is part of the support plan. If your Mexico site has no network team, we manage the perimeter for you and report to headquarters in English. And if you only want to know where you stand, we run an express audit of console access.
And in your Mexico operation?
If nobody can tell you today who holds the Check Point password for the Mexico site, that is the first item. The version is the second. Locking down the console is the third.
Book your free assessment — we reply the same business day.
Your path
Running IT in Mexico from abroad
30 of 32- Smart hands ✓ Read You are here 2 min
- Remote support ✓ Read You are here 3 min
- Nearshoring checklist ✓ Read You are here 2 min
- Retail rollouts ✓ Read You are here 2 min
- Fake IT support ✓ Read You are here 3 min
- Backups that restore ✓ Read You are here 3 min
- Secure M365 ✓ Read You are here 3 min
- Windows 10 deadline ✓ Read You are here 4 min
- Audit app access ✓ Read You are here 3 min
- CEO fraud ✓ Read You are here 4 min
- Office 2016 cutoff ✓ Read You are here 3 min
- Patch today ✓ Read You are here 4 min
- Patch VMware ✓ Read You are here 4 min
- Office 2021 EOL ✓ Read You are here 3 min
- Starlink for sites ✓ Read You are here 3 min
- Cardless access ✓ Read You are here 4 min
- Control AI on PCs ✓ Read You are here 4 min
- ScreenConnect flaw ✓ Read You are here 4 min
- Server 2022 EOL ✓ Read You are here 3 min
- Exposed cameras ✓ Read You are here 3 min
- Domain trust fix ✓ Read You are here 4 min
- Patch Cisco ISE ✓ Read You are here 3 min
- Protect the plant ✓ Read You are here 3 min
- Move to 25H2 ✓ Read You are here 4 min
- Outages and UPS ✓ Read You are here 3 min
- IT maintenance ✓ Read You are here 4 min
- Third-party scripts ✓ Read You are here 3 min
- License audit ✓ Read You are here 4 min
- Bajío fiber corridor ✓ Read You are here 3 min
- Check Point flaw ✓ Read You are here 4 min
- Cashless payments ✓ Read You are here 3 min
- AI that hacks alone ✓ Read You are here 3 min
- Field services →