Check Point Patches Critical SmartConsole Auth Bypass Exploited in the Wild
Check Point has shipped emergency security updates to remediate multiple high-severity flaws affecting its Security Management and Multi-Domain Security Management (MDSM) products, including a critical authentication bypass that is being actively exploited against a small number of customers. The most severe issue, tracked as CVE-2026-16232 with a CVSS score of 9.3, resides in the SmartConsole login process and enables an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. According to CVE.org, successful exploitation permits modification of security policies and configurations, with exploitation requiring direct internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Lotem Finkelstein, vice president of research at Check Point, confirmed awareness of targeted attacks against customers and noted the issue only affects environments where Management is exposed directly to the internet without IP restrictions.
Check Point has published indicators of compromise tied to the campaign, including the IP addresses 151.241.99[.]207, 151.241.99[.]233, 158.62.198[.]182, 192.142.10[.]99, 139.28.37[.]250, and 194.213.18[.]137. Defenders can use a WHOIS lookup to investigate ownership of these addresses and a port scanner to verify whether internal management interfaces are inadvertently exposed on the public internet. Beyond CVE-2026-16232, the vendor also patched CVE-2026-62144 (CVSS 9.3), a second authentication bypass allowing unauthenticated remote attackers to execute administrative commands such as run-script and exec-command on Security Gateways, and CVE-2026-62145 (CVSS 7.5), an improper privilege management flaw in the Gaia Portal that lets read-only users escalate to root. All three vulnerabilities impact Check Point branches R77.30 through R82.10, and the July 22 Jumbo hotfix is recommended for affected deployments.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) catalog, mandating that Federal Civilian Executive Branch (FCEB) agencies apply remediations by July 25, 2026. Check Point's guidance urges administrators to install the hotfix immediately, restrict Trusted Clients to known IP addresses and subnets, and place the Management Server behind a firewall to prevent direct internet exposure. Organizations managing hybrid infrastructure should also run a SSL/TLS checker against their management endpoints to ensure encrypted access is enforced and certificate configurations have not been weakened. With active exploitation confirmed and multiple CVSS 9.3 flaws in play, the incident underscores the persistent risk of exposing administrative consoles and the importance of layered network controls around identity and access management infrastructure.