INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

SmartConsole Zero-Day Exploit Allows Full Admin Access

| 2026-07-23 08:33 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The Check Point patches actively exploited SmartConsole authentication bypass flaw, a critical vulnerability affecting Security Management and Multi-Domain Security Management servers. The flaw allows unauthenticated remote attackers to execute administrative actions on the management server, including run-script and exec-command operations on security gateways. To mitigate the attack, customers are advised to restrict trusted clients to approved IP addresses only, protect management access with firewall rules, and ensure implied control connection rules are enabled. A July 22 hotfix is also recommended for all affected systems, which includes restricting trusted clients to approved IP addresses or subnets and protecting management access through firewall rules allowing only authorized sources.
Technical Mitigations AI-generated
* Restrict SmartConsole Trusted Clients to trusted IP addresses only (avoid using "Any") and protect Management Server access with firewall rules. * Ensure implied control connection rules are enabled on the Management Server, which can help prevent unauthorized access. * Review logs for connections involving known attacker IP addresses to detect potential compromise.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

151.241.•••.•••
158.62.•••.•••
151.241.•••.•••
192.142.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
QilinQilin CVE-2026-62145CVE-2026-62145 CVE-2026-16232CVE-2026-16232 CVE-2024-24919CVE-2024-24919 CVE-2026-62144CVE-2026-62144 CVE-2026-50751CVE-2026-50751
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎July 22
Threat actors exploited a SmartConsole authentication bypass flaw in R80.30 versions by using the July 22 Jumbo hotfix to gain unauthorized access through restricted Trusted Clients.
organisation R80
organisation R80.20 R80.30
‎Jul 23, 2026
Threat actors exploited a previously unknown vulnerability in Check Point's SmartConsole, allowing them to bypass its authentication mechanisms.
‎2026/07/23
Check Point released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild.
infrastructure 9.3
organisation Security Management
organisation Check Point
financial 04 BOD
organisation Check Point SmartConsole
organisation GUI
organisation Security Gateways
infrastructure 151.241.99
infrastructure 158.62.198
infrastructure 192.142.10
infrastructure 139.28.37
infrastructure 194.213.18
organisation Multi-Domain Security Management
organisation MDS
organisation Vulnerability / Network Security
organisation Lotem Finkelstein
organisation IP
organisation R80
organisation R80.10
organisation R80.20
organisation R81
organisation Management
organisation the Management
organisation Trusted Clients
organisation SmartConsole Trusted Clients
organisation Check Point Security Management
organisation CVE-2026-62145
organisation SmartConsole
organisation SecurityAffairs
organisation Logs & Monitor / Logs & Events > Audit Logs View
organisation EDR
organisation CVE.org
organisation Gaia Portal
‎Saturday, July 25
Threat actors exploited a SmartConsole authentication bypass flaw in Check Point patches.
general_metric 26 Binding Operational Directive
‎July 25, 2026
Threat actors exploited a vulnerability in the SmartConsole authentication system to bypass security controls.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Federal Civilian Executive Branch
attribution FCEB
Tactical Metrics
Metrics
infrastructure
‎9.3
Software Version
Metrics
infrastructure
‎151.241.99
Software Version
Metrics
infrastructure
‎158.62.198
Software Version
Metrics
infrastructure
‎192.142.10
Software Version
Metrics
infrastructure
‎139.28.37
Software Version
Metrics
infrastructure
‎194.213.18
Software Version
Metrics
financial
4
Bod
Intelligence Sources