CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Check Point Patches Actively Exploited SmartConsole Authentication Bypass Flaw CVE-2026-16232

July 23, 2026

Check Point has released security updates to address multiple vulnerabilities in its Security Management and Multi-Domain Management (MDSM) products, including a critical authentication bypass flaw (CVE-2026-16232, CVSS 9.3) that is being actively exploited in the wild. The vulnerability affects the SmartConsole login process, allowing an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. Successful exploitation enables attackers to modify security policies and configurations. The flaw requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients.

Check Point’s VP of Research, Lotem Finkelstein, confirmed a small number of customers have been targeted, and the company has notified them. The vendor shared indicators of compromise (IoCs) including IP addresses 151.241.99[.]207, 151.241.99[.]233, 158.62.198[.]182, 192.142.10[.]99, 139.28.37[.]250, and 194.213.18[.]137.

Two additional flaws were also patched: CVE-2026-62144 (CVSS 9.3), an authentication bypass in Security Management and Multi-Domain Security Management allowing unauthenticated remote attackers to execute administrative commands; and CVE-2026-62145 (CVSS 7.5), an improper privilege management vulnerability in Gaia Portal allowing authenticated read-only users to execute commands with root privileges. All three issues impact versions R77.30 through R82.10.

Check Point recommends applying the July 22 Jumbo hotfix, limiting Trusted Clients to trusted IP addresses/subnets, securing Management access with a firewall, and restricting access to trusted IP addresses. CISA has added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) catalog, requiring FCEB agencies to apply fixes by July 25, 2026.

CVEs: CVE-2026-16232, CVE-2026-62144, CVE-2026-62145

Companies: Check Point, CISA

Products: Check Point SmartConsole, Check Point Security Management, Check Point Multi-Domain Management (MDSM), Check Point Gaia Portal