Critical Check Point Authentication Flaw Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about CVE-2026-16232, a critical authentication vulnerability in Check Point SmartConsole that is being actively exploited. The flaw, rated 9.3 on the CVSS scale, affects Check Point Security Management and Multi-Domain Management platforms, allowing unauthenticated remote attackers to obtain an application login token and gain full administrative access to affected systems.
The vulnerability was discovered during an internal BLAST (Business Logic Attack Surface Testing) review under Check Point’s Frontier AI Readiness Program. Exploitation has been confirmed in real-world attacks, though limited to environments where management interfaces are exposed to the internet without IP-based restrictions. Attackers could leverage this access to modify security policies, deploy malicious configurations, or pivot deeper into enterprise networks, risking full infrastructure compromise.
CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, emphasizing the need for immediate patching. Affected versions include R81.10, R81.20, R82, and R82.10, with older versions also potentially vulnerable. Check Point has released a Jumbo Hotfix (July 22, 2026) to remediate the issue and strengthen system resilience.
In the same advisory, Check Point disclosed two additional high-severity vulnerabilities:
- CVE-2026-62144 (CVSS 9.3): Another authentication bypass and privilege escalation flaw in management systems, though not yet exploited.
- CVE-2026-62145 (CVSS 7.5): A local privilege escalation issue in GaiaOS WebUI, currently unexploited.
Security teams are advised to restrict SmartConsole and management access to trusted IP addresses, enforce firewall protections, and monitor for indicators of compromise, including:
- 151.241.99[.]207
- 151.241.99[.]233
- 158.62.198[.]182
- 192.142.10[.]99
- 139.28.37[.]250
- 194.213.18[.]137
The incident underscores the risks of exposed management interfaces and the necessity of proactive patching, strict access controls, and continuous monitoring to mitigate evolving threats.
Source: https://cybersecuritynews.com/check-point-vulnerability-exploited/
Check Point TPRM report: https://www.rankiteo.com/company/check-point-software-technologies
"id": "che1784787889",
"linkid": "check-point-software-technologies",
"type": "Vulnerability",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Cybersecurity',
'name': 'Check Point',
'type': 'Cybersecurity Company'}],
'attack_vector': 'Remote Exploitation',
'date_publicly_disclosed': '2026-07-22',
'description': 'The U.S. Cybersecurity and Infrastructure Security Agency '
'(CISA) has issued an urgent warning about CVE-2026-16232, a '
'critical authentication vulnerability in Check Point '
'SmartConsole that is being actively exploited. The flaw, '
'rated 9.3 on the CVSS scale, affects Check Point Security '
'Management and Multi-Domain Management platforms, allowing '
'unauthenticated remote attackers to obtain an application '
'login token and gain full administrative access to affected '
'systems. The vulnerability was discovered during an internal '
'BLAST (Business Logic Attack Surface Testing) review under '
'Check Point’s Frontier AI Readiness Program. Exploitation has '
'been confirmed in real-world attacks, though limited to '
'environments where management interfaces are exposed to the '
'internet without IP-based restrictions. Attackers could '
'leverage this access to modify security policies, deploy '
'malicious configurations, or pivot deeper into enterprise '
'networks, risking full infrastructure compromise.',
'impact': {'operational_impact': 'Full administrative access, modification of '
'security policies, deployment of malicious '
'configurations, potential full '
'infrastructure compromise',
'systems_affected': 'Check Point Security Management and '
'Multi-Domain Management platforms'},
'lessons_learned': 'The incident underscores the risks of exposed management '
'interfaces and the necessity of proactive patching, '
'strict access controls, and continuous monitoring to '
'mitigate evolving threats.',
'post_incident_analysis': {'corrective_actions': 'Proactive patching, strict '
'access controls, continuous '
'monitoring',
'root_causes': 'Exposed management interfaces '
'without IP-based restrictions'},
'recommendations': ['Apply the Jumbo Hotfix (July 22, 2026) immediately',
'Restrict SmartConsole and management access to trusted '
'IP addresses',
'Enforce firewall protections',
'Monitor for indicators of compromise'],
'references': [{'source': 'CISA Advisory'}],
'regulatory_compliance': {'regulatory_notifications': 'CISA Known Exploited '
'Vulnerabilities (KEV) '
'catalog'},
'response': {'containment_measures': 'Restrict SmartConsole and management '
'access to trusted IP addresses, enforce '
'firewall protections',
'enhanced_monitoring': 'Monitor for indicators of compromise',
'remediation_measures': 'Apply Jumbo Hotfix (July 22, 2026)'},
'title': 'Critical Check Point Authentication Flaw Actively Exploited in the '
'Wild',
'type': 'Authentication Bypass',
'vulnerability_exploited': 'CVE-2026-16232'}