Back to Feed
VulnerabilitiesJul 23, 2026

New Check Point Zero-Day Vulnerability Exploited in the Wild

Check Point zero-day CVE-2026-16232 exploited in the wild, affecting management products.

Summary

Check Point has confirmed that a critical zero-day vulnerability, CVE-2026-16232, in its Security Management and Multi-Domain Management products has been exploited by attackers. The authentication bypass flaw allows for administrator-level access to change security policies. While Check Point has released patches and mitigations, CISA has added the CVE to its KEV catalog, mandating federal agencies to address it by July 25.

Full text

Check Point has notified customers that a critical zero-day vulnerability discovered recently in its products has been exploited in the wild. The exploited vulnerability is tracked as CVE-2026-16232 and it affects the cybersecurity company’s Security Management and Multi-Domain Management products. The flaw has been described as an authentication bypass issue that allows an attacker to obtain an application login token. The token can then be used to log in via the SmartConsole with full administrator privileges, and make changes to the security policy and configuration. “Check Point confirmed that this vulnerability has been observed in the wild, affecting a limited number of customers whose Management environments were directly exposed to the Internet without IP restrictions,” Check Point said. The security firm has released patches and mitigations, and made available indicators of compromise (IoCs) for the attacks exploiting CVE-2026-16232. Targeted customers have been privately notified. CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday, instructing federal agencies to address it by July 25. Advertisement. Scroll to continue reading. This is the third Check Point vulnerability added to CISA’s KEV list, after CVE-2026-50751, which attackers exploited as a zero-day in May, and CVE-2024-24919, which threat actors leveraged in 2024. In addition to CVE-2026-16232, Check Point’s latest updates patch CVE-2026-62144, a critical authentication bypass and privilege escalation flaw affecting Security Management and Multi-Domain Management, and CVE-2026-62145, a high-severity local privilege escalation affecting Firewall, Multi-Domain Management, and Multi-Domain Log Server products. All three vulnerabilities were discovered internally by Check Point, but an analysis revealed that CVE-2026-16232 had already been exploited as a zero-day. It’s unclear who is behind the latest attacks, but the Qilin ransomware group was recently observed targeting Check Point appliances. Related: Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Related: Exploitation of ServiceNow Vulnerability Seen Days After Disclosure Related: SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of AttacksOracle Patches Over 1,400 Vulnerabilities With Quarterly Security UpdatesRansomware Group Threatening to Leak Data Stolen From Coca-Cola’s FairlifeOpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support DataExploitation of ServiceNow Vulnerability Seen Days After DisclosureSonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before PatchNew Index Tracks Material Breaches — And Refuses to Add Up the Losses Latest News Assaf Keren Appointed New CISO of MetaUS Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS DevicesSuno, Paidwork Data Breaches Affect Tens of Millions of AccountsPalo Alto Networks to Acquire Observability Platform Provider EmbraceFlaw in Adobe Extension With 300M Installs Enabled WhatsApp Data TheftWhen Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account TakeoverVibe-Coded Apps Riddled With Exploitable Security FlawsStrongestLayer Raises $4.1 Million in Seed Funding Extension Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveAssaf Keren, who previously served as CSO/CISO at Qualtrics and PayPal, is Meta's new CISO.Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.AJ Shipley has been appointed Chief Product Officer at CrowdStrike.More People On The MoveExpert Insights When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. (Joshua Goldfarb) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-16232
  • cve — CVE-2026-50751
  • cve — CVE-2024-24919
  • cve — CVE-2026-62144
  • cve — CVE-2026-62145

Entities

Check Point (vendor)Security Management (product)Multi-Domain Management (product)Firewall (product)Multi-Domain Log Server (product)Qilin ransomware group (threat_actor)