ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)

criticalVulnerability exploited in the wildimportance 60CVE-2026-16232CVE-2026-62144CVE-2026-62145

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-16232
Authentication Bypass in Check Point SmartConsole Grants Full Admin Access

Check Point SmartConsole, the administrative client used to manage Quantum Security Management and Multi-Domain Security Management, contains an authentication bypass (CWE-287) in its login process that allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. Exploitation is possible when the Management Server IP address is reachable from the internet and the configuration does not restrict Trusted Clients. A successful attacker can modify security policies and security configurations, effectively taking control of firewall management. Any organization running an internet-exposed Check Point management server without Trusted Client restrictions is affected, though Check Point reports exploitation has impacted only a very small number of customers. The flaw was added to CISA's KEV on 2026-07-22, is actively exploited, and press reports indicate public proof-of-concept code has been released.

Do: Apply the fix released in Check Point's advisory for CVE-2026-16232 by updating SmartConsole and the associated Quantum/MDS management software; no fixed version numbers were provided in this data, so confirm them against the vendor bulletin. As an interim mitigation, restrict internet access to the Management Server IP address and configure Trusted Clients so SmartConsole connections are accepted only from known administrator addresses. Review management logs for unexpected logins, unauthenticated token issuance, or unfamiliar administrator sessions, and complete remediation per CISA BOD 26-04 given the KEV listing.

9.372% KEV
  • Check Point SmartConsole
  • Check Point Quantum Security Management
  • Check Point Multi-Domain Security Management
largeplausibly tens of thousands of Check Point management deployments, though the vulnerable subset is only those with an internet-exposed Management Server and no…
CVE-2026-62144
Authentication Bypass in Check Point Security and Multi-Domain Security Management

CVE-2026-62144 is an authentication bypass (CWE-287) in Check Point Security Management and Multi-Domain Security Management that lets an unauthenticated remote attacker execute administrative commands on the Management Server. It is triggered when an attacker can reach the Management Server over the network without firewall protection, or when the management configuration does not restrict Trusted Clients. Successful exploitation gives the attacker full administrative command execution on the management server and may also allow command execution on the managed Security Gateways behind it. Any organization running these Check Point management products where the management interface is reachable without Trusted Clients restriction is affected. As of now there is no public proof-of-concept, it is not in CISA KEV, and no confirmed in-the-wild exploitation is known, although its EPSS of 20.8% (97th percentile) indicates an elevated likelihood of exploitation within 30 days.

Do: Upgrade Security Management and Multi-Domain Security Management to the patched release per Check Point's official advisory. As interim mitigation, restrict Trusted Clients on the management server and firewall network access to management interfaces, and audit existing configurations for missing Trusted Clients restrictions. Separately, ensure the actively exploited SmartConsole authentication bypass (CVE-2026-16232) is also patched, since it affects the same management ecosystem.

9.121%
  • Check Point Security Management
  • Check Point Multi-Domain Security Management
largetens of thousands of management server deployments, of which only the subset with management interfaces reachable without Trusted Clients restriction are…
CVE-2026-62145
A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

NVD description · AI analysis pending
7.58%
Full article633 words · extracted from helpnetsecurity.com · click to collapse

Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls).

“An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration,” the company said.

The vulnerability is being exploited, they confirmed, and a “handful” of customers have been affected (and notified).

Remediation, mitigation, investigation

CVE-2026-16232 affects a number of supported and end-of-service versions of Check Point Security Management and Multi-Domain Security Management. Hotfixes are available for the supported versions: R81.20, R82, and R82.10

“Successful remote exploit requires internet access to the Management Server IP address and no restrictions on Trusted Clients (GUI clients),” Check Point noted.

Thus, if customers can’t implement one of the provided “jumbo hotfixes” immediately, they can mitigate the risk of exploitation by limiting Trusted Clients to trusted IP addresses/subnets, and by protecting Management access with Firewall and restricting access to trusted IP addresses.

Check Point also shared a list of IP addresses associated with the attacks, and instructed customers on how to use this information to verify whether they’ve been affected.

“The Management Server is not simply another administrative system. It controls critical security functions such as: security policies, administrator permissions, managed gateways, VPN configurations, Threat Prevention settings, policy installation, logging and monitoring,” a MVP contributor to Check Point’s CheckMates community forum noted.

“A vulnerability affecting the Management Plane can undermine the trust model of the entire security architecture. Even organizations whose Management Servers are not directly exposed to the Internet should not postpone remediation. Network restrictions reduce exposure, but they do not remove the vulnerable code.”

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog, and requires civilian US federal agencies to address it by July 25 and investigate whether they’ve been hit by attackers.

Additional flaws fixed

The jumbo hotfixes released by Check Point also fix:

  • CVE-2026-62144, a similarly critical vulnerability that allows unauthenticated attackers to execute administrative commands on the Management Server and then allows them to execute commands on managed security gateways
  • CVE-2026-62145, a vulnerability in Gaia Portal – the web-based management interface for Check Point’s Linux-based operating system that runs on management servers and security gateways – that allows an authenticated attacker with read-only access to run commands as root.

These are not known to be actively exploited, and the latter also affects Check Point firewalls (except Check Point Spark Gateways), not just the management servers.

UPDATE (July 30, 2026, 11:25 a.m. ET):

Rapid7 released a root-cause analysis of CVE-2026-16232 and a proof-of-concept (PoC) exploit script for checking whether a target is vulnerable or has been patched.

Xavier Bellekens, CEO of cyber deception and threat intelligence firm Lupovis, told Help Net Security that their honeypots flagged activity consistent with automated exploitation of CVE-2026-16232 or CVE-2026-62144 on April 29, 2026.

“An adversary attempted to authenticate and immediately enumerate the managed gateway environment in a sequence. After a review of the different elements, we observed pre-disclosure probing of the Check Point Management API (/web_api/login, show-gateways-and-servers) consistent with the management-plane authentication-bypass cluster of CVE-2026-16232 and CVE-2026-62144,” he told us.

“We linked the activity to these vulnerabilities because the requests targeted the affected Check Point batch API endpoints, and the request structure and payload matched the published exploitation path remote code execution issues. We classify these as exploitation attempts rather than general scanning because the actors were sending requests designed to exercise the vulnerable functionality, not simply checking whether the endpoints existed.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/07/23/check-point-vulnerability-cve-2026-16232/