Check Point patches actively exploited SmartConsole authentication bypass flaw
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-16232 | Authentication Bypass in Check Point SmartConsole Grants Full Admin Access Check Point SmartConsole, the administrative client used to manage Quantum Security Management and Multi-Domain Security Management, contains an authentication bypass (CWE-287) in its login process that allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. Exploitation is possible when the Management Server IP address is reachable from the internet and the configuration does not restrict Trusted Clients. A successful attacker can modify security policies and security configurations, effectively taking control of firewall management. Any organization running an internet-exposed Check Point management server without Trusted Client restrictions is affected, though Check Point reports exploitation has impacted only a very small number of customers. The flaw was added to CISA's KEV on 2026-07-22, is actively exploited, and press reports indicate public proof-of-concept code has been released. Do: Apply the fix released in Check Point's advisory for CVE-2026-16232 by updating SmartConsole and the associated Quantum/MDS management software; no fixed version numbers were provided in this data, so confirm them against the vendor bulletin. As an interim mitigation, restrict internet access to the Management Server IP address and configure Trusted Clients so SmartConsole connections are accepted only from known administrator addresses. Review management logs for unexpected logins, unauthenticated token issuance, or unfamiliar administrator sessions, and complete remediation per CISA BOD 26-04 given the KEV listing. | 9.3 | 72% | KEV |
| largeplausibly tens of thousands of Check Point management deployments, though the vulnerable subset is only those with an internet-exposed Management Server and no… | |
| CVE-2026-62144 | Authentication Bypass in Check Point Security and Multi-Domain Security Management CVE-2026-62144 is an authentication bypass (CWE-287) in Check Point Security Management and Multi-Domain Security Management that lets an unauthenticated remote attacker execute administrative commands on the Management Server. It is triggered when an attacker can reach the Management Server over the network without firewall protection, or when the management configuration does not restrict Trusted Clients. Successful exploitation gives the attacker full administrative command execution on the management server and may also allow command execution on the managed Security Gateways behind it. Any organization running these Check Point management products where the management interface is reachable without Trusted Clients restriction is affected. As of now there is no public proof-of-concept, it is not in CISA KEV, and no confirmed in-the-wild exploitation is known, although its EPSS of 20.8% (97th percentile) indicates an elevated likelihood of exploitation within 30 days. Do: Upgrade Security Management and Multi-Domain Security Management to the patched release per Check Point's official advisory. As interim mitigation, restrict Trusted Clients on the management server and firewall network access to management interfaces, and audit existing configurations for missing Trusted Clients restrictions. Separately, ensure the actively exploited SmartConsole authentication bypass (CVE-2026-16232) is also patched, since it affects the same management ecosystem. | 9.1 | 21% |
| largetens of thousands of management server deployments, of which only the subset with management interfaces reachable without Trusted Clients restriction are… | ||
| CVE-2026-62145 | A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges. A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges. NVD description · AI analysis pending | 7.5 | 8% | — | — |
Full article398 words · extracted from securityaffairs.com · click to collapse

Check Point addressed a critical authentication bypass flaw, tracked as CVE-2026-16232, in SmartConsole that is being actively exploited.
Check Point has released security updates to fix multiple vulnerabilities, including CVE-2026-16232 (CVSS score of 9.3), a critical authentication bypass flaw affecting Security Management and Multi-Domain Management (MDSM).
The vulnerability, which is under active exploitation, allows unauthenticated remote attackers to obtain a SmartConsole login token and gain full administrative access.
“An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration. Check Point is aware that this vulnerability is being exploited, impacting a very small number of customers.” reads the advisory. “Successful remote exploit requires internet access to the Management Server IP address and no restrictions on Trusted Clients (GUI clients).”
Successful exploitation requires the Management Server to be accessible from the internet and Trusted Clients (GUI client) access restrictions to be disabled.
Check Point said it is aware of a limited number of customers targeted through CVE-2026-16232 and has already notified the affected organizations. The following attacker IP addresses have been identified as indicators of compromise (IoCs):
- 151.241.99[.]207
- 151.241.99[.]233
- 158.62.198[.]182
- 192.142.10[.]99
- 139.28.37[.]250
- 194.213.18[.]137
The flaw impacts the following products and versions:
- Products: Security Management Server, Multi-Domain Security Management Server (MDS)
- Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81 R81.10, R81.20, R82, R82.10
To mitigate the attack, restrict SmartConsole Trusted Clients to trusted IP addresses only (avoid using “Any”), protect Management Server access with firewall rules, and ensure implied control connection rules are enabled. Administrators should also review logs for connections involving known attacker IP addresses to detect potential compromise.
Check Point also addressed two additional security vulnerabilities:
- CVE-2026-62144 (CVSS score of 9.3): A critical authentication bypass flaw in Security Management and Multi-Domain Security Management that enables unauthenticated remote attackers to execute administrative actions on the Management Server, including
run-scriptandexec-commandoperations on Security Gateways. - CVE-2026-62145 (CVSS score of 7.5): An improper privilege management issue in the Gaia Portal that allows authenticated users with read-only access to escalate privileges and execute commands as root.
Customers should install the July 22 Jumbo hotfix, restrict Trusted Clients to approved IP addresses or subnets, and protect Management access through firewall rules allowing only authorized sources.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Check Point)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/195848/hacking/check-point-patches-actively-exploited-smartconsole-authentication-bypass-flaw.html