ACTIVE EXPLOITATION · CVE-2026-16232

Check Point Patches Actively Exploited SmartConsole Auth Bypass Granting Full Admin Access

Check Point has patched CVE-2026-16232, a CVSS 9.3 authentication bypass in the SmartConsole login flow that lets unauthenticated attackers mint admin tokens on internet-exposed Management Servers.

Matt Lucas  |  July 23, 2026  |  5 min
Editorial hero illustration
CVEs in this postCVE-2026-16232CVE-2026-50522CVE-2026-62144CVE-2026-62145CVE-2026-6875Live detections →All RedEye CVEs →
9.3
CVSS, exploited in wild
3
CVEs patched July 22
10
affected versions (R77.30-R82.10)
Jul 25
CISA KEV deadline
Detected by CaverLive detection for CVE-2026-62144 in the RedEye Intel Feed →
TL;DR
  • What: Check Point patched CVE-2026-16232, a CVSS 9.3 authentication bypass in the SmartConsole login process that is under active exploitation, alongside two other management-plane flaws (CVE-2026-62144, CVSS 9.3; CVE-2026-62145, CVSS 7.5).
  • Impact: An unauthenticated remote attacker can obtain an application login token, authenticate with full administrative privileges, and rewrite security policy on the Management Server that controls your firewall estate.
  • Fix / mitigation: Apply the July 22 Jumbo hotfix, restrict Trusted Clients to specific IPs/subnets, and put Management access behind the firewall; CISA's KEV deadline for federal agencies is July 25, 2026.
  • Who's at risk: Any organization running Check Point Security Management or Multi-Domain Management R77.30 through R82.10 with the Management Server reachable from the internet and no Trusted Clients restrictions.

Check Point has shipped emergency fixes for three vulnerabilities in its Security Management and Multi-Domain Security Management (MDSM) products, and one of them is already being used in real attacks. CVE-2026-16232 (CVSS 9.3) is an authentication bypass in the SmartConsole login process that hands an unauthenticated remote attacker an application login token, which they can then replay to authenticate with full administrative privileges. That is not a foothold on an edge device. That is direct control of the console that writes firewall policy for your entire Check Point estate.

Check Point's VP of research, Lotem Finkelstein, confirmed a small number of customers have been targeted and have been notified. The company has not said who is behind the activity, what the post-exploitation objectives were, or when the attacks were first detected. CISA moved quickly regardless: the flaw is now in the Known Exploited Vulnerabilities catalog with a remediation deadline of July 25, 2026 for Federal Civilian Executive Branch agencies. That is a three-day window, which tells you how CISA is reading the risk.

Why a management-plane bypass is worse than a gateway bug

The Management Server is the control plane for every Security Gateway it manages. Per the CVE.org description, successful exploitation lets the attacker modify security policies and security configurations. In practice that means an attacker with an admin token can open pinholes through your perimeter, disable inspection blades, push modified policy to every managed gateway, and create persistence that looks like legitimate administrative change. Firewall audit trails are only as trustworthy as the console that produces them, and this flaw compromises the console itself.

The exploitation preconditions are narrow but common. Remote exploitation requires two things: the Management Server IP is reachable from the internet, and the Trusted Clients (GUI clients) configuration does not restrict which source addresses can connect. Trusted Clients defaults are frequently left wide open in real deployments because admins connect from changing locations, VPN pools, or MSP networks. If your management interface answers to any source IP, you are in the exploitable population.

Confirmed exploitation, IoCs published

Check Point released six attacker IP addresses tied to the observed activity: 151.241.99.207, 151.241.99.233, 158.62.198.182, 192.142.10.99, 139.28.37.250, and 194.213.18.137. Search firewall, management API, and SmartConsole authentication logs for connections from these addresses, and treat any hit as a potential full management-plane compromise, not just a scan.

Two more flaws in the same patch batch

CVE-2026-16232 is the headline, but the July 22 release fixes two additional issues that deserve attention. CVE-2026-62144 also carries a CVSS score of 9.3: it is a separate authentication bypass in Security Management and MDSM that lets an unauthenticated remote attacker execute administrative commands on the Management Server, including run-script and exec-command against managed Security Gateways. That is arbitrary command execution on both the management tier and the enforcement tier, gated by the same precondition as the exploited flaw: management access reachable without firewall protection or Trusted Clients restrictions.

CVE-2026-62145 (CVSS 7.5) is an improper privilege management bug in the Gaia Portal. An authenticated user holding read-only Gaia Portal privileges can escalate to command execution as root. On its own it requires credentials, but chained behind either auth bypass, or used by a compromised low-privilege operator account, it converts limited access into full OS control of the management appliance.

Affected versions

All three vulnerabilities affect ten release trains: R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, and R82.10. Note that several of these versions are old enough that many organizations run them on appliances nobody has touched in years. If you inherited a Check Point management box during an acquisition or have a legacy MDSM domain still on R77.30 or R80.x, it is in scope, and those forgotten boxes are exactly the ones most likely to be internet-exposed with default Trusted Clients settings.

What to do now

If you find IoC hits, assume policy tampering

Because this flaw grants full administrative privileges, remediation after a confirmed hit is not just patching. Treat the Management Server as compromised: rotate all administrator credentials and API keys, revoke active sessions, compare deployed gateway policy against the last trusted revision, and rebuild the management appliance if you cannot establish a clean baseline.

The bigger pattern

This is the latest entry in a sustained trend of attackers targeting the management planes of security infrastructure itself: firewalls, VPN concentrators, and the consoles that run them. These systems hold the highest privilege in the network, are frequently exempted from the exposure standards applied to ordinary servers, and often lag on patching because downtime windows are hard to get. The precondition for both critical CVEs here, management exposed directly to the internet without IP restrictions, is a configuration decision, not a vulnerability. Fix the patch gap this week, but fix the exposure permanently. No firewall management interface should be answering to the whole internet in 2026.

Questions about your exposure?

RedEye Security provides assessments for organizations that need to understand their real risk.

Talk to us