ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

criticalVulnerability exploited in the wildimportance 60CVE-2026-16232CVE-2026-62144CVE-2026-62145

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-16232
Authentication Bypass in Check Point SmartConsole Grants Full Admin Access

Check Point SmartConsole, the administrative client used to manage Quantum Security Management and Multi-Domain Security Management, contains an authentication bypass (CWE-287) in its login process that allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges. Exploitation is possible when the Management Server IP address is reachable from the internet and the configuration does not restrict Trusted Clients. A successful attacker can modify security policies and security configurations, effectively taking control of firewall management. Any organization running an internet-exposed Check Point management server without Trusted Client restrictions is affected, though Check Point reports exploitation has impacted only a very small number of customers. The flaw was added to CISA's KEV on 2026-07-22, is actively exploited, and press reports indicate public proof-of-concept code has been released.

Do: Apply the fix released in Check Point's advisory for CVE-2026-16232 by updating SmartConsole and the associated Quantum/MDS management software; no fixed version numbers were provided in this data, so confirm them against the vendor bulletin. As an interim mitigation, restrict internet access to the Management Server IP address and configure Trusted Clients so SmartConsole connections are accepted only from known administrator addresses. Review management logs for unexpected logins, unauthenticated token issuance, or unfamiliar administrator sessions, and complete remediation per CISA BOD 26-04 given the KEV listing.

9.372% KEV
  • Check Point SmartConsole
  • Check Point Quantum Security Management
  • Check Point Multi-Domain Security Management
largeplausibly tens of thousands of Check Point management deployments, though the vulnerable subset is only those with an internet-exposed Management Server and no…
CVE-2026-62144
Authentication Bypass in Check Point Security and Multi-Domain Security Management

CVE-2026-62144 is an authentication bypass (CWE-287) in Check Point Security Management and Multi-Domain Security Management that lets an unauthenticated remote attacker execute administrative commands on the Management Server. It is triggered when an attacker can reach the Management Server over the network without firewall protection, or when the management configuration does not restrict Trusted Clients. Successful exploitation gives the attacker full administrative command execution on the management server and may also allow command execution on the managed Security Gateways behind it. Any organization running these Check Point management products where the management interface is reachable without Trusted Clients restriction is affected. As of now there is no public proof-of-concept, it is not in CISA KEV, and no confirmed in-the-wild exploitation is known, although its EPSS of 20.8% (97th percentile) indicates an elevated likelihood of exploitation within 30 days.

Do: Upgrade Security Management and Multi-Domain Security Management to the patched release per Check Point's official advisory. As interim mitigation, restrict Trusted Clients on the management server and firewall network access to management interfaces, and audit existing configurations for missing Trusted Clients restrictions. Separately, ensure the actively exploited SmartConsole authentication bypass (CVE-2026-16232) is also patched, since it affects the same management ecosystem.

9.121%
  • Check Point Security Management
  • Check Point Multi-Domain Security Management
largetens of thousands of management server deployments, of which only the subset with management interfaces reachable without Trusted Clients restriction are…
CVE-2026-62145
A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

NVD description · AI analysis pending
7.58%
Full article427 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJul 23, 2026Vulnerability / Network Security

Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild.

The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

"Successful exploitation allows the attacker to modify security policies and security configurations," according to a description of the flaw in CVE.org. "Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients."

Lotem Finkelstein, vice president of research at Check Point, said the company is aware of a handful of customers being targeted by this flaw, and that it has already notified them. It did not disclose the nature of the attacks or when they were discovered.

"This only affects a very specific configuration - when Management is exposed directly to the internet without IP restrictions," Finkelstein added.

The cybersecurity vendor has shared the below indicators of compromise (IoCs) associated with the activity -

  • 151.241.99[.]207
  • 151.241.99[.]233
  • 158.62.198[.]182
  • 192.142.10[.]99
  • 139.28.37[.]250
  • 194.213.18[.]137

Patches have also been released for two other flaws -

  • CVE-2026-62144 (CVSS score: 9.3) - An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management that allows an unauthenticated remote attacker to execute administrative commands on the Management Server, including run-script and exec-command on Security Gateway.
  • CVE-2026-62145 (CVSS score: 7.5) - An improper privilege management vulnerability in Check Point Gaia Portal that allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

Like in the case of CVE-2026-16232, successful exploitation of CVE-2026-62144 requires management access without Firewall protection or no restrictions on Trusted Clients (GUI clients). All three issues impact the following versions -

  • R77.30
  • R80
  • R80.10
  • R80.20
  • R80.30
  • R81
  • R81.10
  • R81.20
  • R82
  • R82.10

Customers are recommended to apply the July 22 Jumbo hotfix, limit Trusted Clients (GUI clients) to trusted IP addresses/subnets, secure Management access with Firewall, and restrict access to trusted IP addresses.

The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by July 25, 2026.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/07/check-point-patches-exploited.html