Back to Feed
VulnerabilitiesJul 23, 2026

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

Check Point patches critical SmartConsole flaw exploited in the wild, granting admin access.

Summary

Check Point has released updates to fix a critical authentication bypass vulnerability (CVE-2026-16232) in its SmartConsole login process, which has been actively exploited. The flaw allows unauthenticated attackers to gain full administrative privileges, enabling them to modify security policies and configurations. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by July 25, 2026.

Full text

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access Ravie LakshmananJul 23, 2026Vulnerability / Network Security Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. "Successful exploitation allows the attacker to modify security policies and security configurations," according to a description of the flaw in CVE.org. "Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients." Lotem Finkelstein, vice president of research at Check Point, said the company is aware of a small number of customers being targeted by this flaw, and that it has already notified them. It did not disclose the nature of the attacks or when they were discovered. "This only affects a very specific configuration - when Management is exposed directly to the internet without IP restrictions," Finkelstein added. The cybersecurity vendor has shared the below indicators of compromise (IoCs) associated with the activity - 151.241.99[.]207 151.241.99[.]233 158.62.198[.]182 192.142.10[.]99 139.28.37[.]250 194.213.18[.]137 Patches have also been released for two other flaws - CVE-2026-62144 (CVSS score: 9.3) - An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management that allows an unauthenticated remote attacker to execute administrative commands on the Management Server, including run-script and exec-command on Security Gateway. CVE-2026-62145 (CVSS score: 7.5) - An improper privilege management vulnerability in Check Point Gaia Portal that allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges. Like in the case of CVE-2026-16232, successful exploitation of CVE-2026-62144 requires management access without Firewall protection or no restrictions on Trusted Clients (GUI clients). All three issues impact the following versions - R77.30 R80 R80.10 R80.20 R80.30 R81 R81.10 R81.20 R82 R82.10 Customers are recommended to apply the July 22 Jumbo hotfix, limit Trusted Clients (GUI clients) to trusted IP addresses/subnets, secure Management access with Firewall, and restrict access to trusted IP addresses. The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by July 25, 2026. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  enterprise security, network security, Patch Management, privilege escalation, Vulnerability ⚡ Top Stories This Week URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code ⭐ Featured Resources What Security Teams Must Defend in the New AI Software Supply Chain Identity Fraud Is Changing Fast. See the Attacks Businesses Face in 2026 What 25 Million Alerts Reveal About the Threats SOCs Ignore How to Find and Control Every Script Running Through Your Marketing Stack Modern SASE Guide: Close the Gaps Traditional Network Security Cannot See

Indicators of Compromise

  • ip — 151.241.99.207
  • ip — 151.241.99.233
  • ip — 158.62.198.182
  • ip — 192.142.10.99
  • ip — 139.28.37.250
  • ip — 194.213.18.137
  • cve — CVE-2026-16232
  • cve — CVE-2026-62144
  • cve — CVE-2026-62145

Entities

SmartConsole (product)Security Management (product)Multi-Domain Management (product)Check Point (vendor)Gaia Portal (product)Security Gateway (product)