- What: Check Point patched CVE-2026-16232, a CVSS 9.3 authentication bypass in the SmartConsole login process that is under active exploitation, alongside two other management-plane flaws (CVE-2026-62144, CVSS 9.3; CVE-2026-62145, CVSS 7.5).
- Impact: An unauthenticated remote attacker can obtain an application login token, authenticate with full administrative privileges, and rewrite security policy on the Management Server that controls your firewall estate.
- Fix / mitigation: Apply the July 22 Jumbo hotfix, restrict Trusted Clients to specific IPs/subnets, and put Management access behind the firewall; CISA's KEV deadline for federal agencies is July 25, 2026.
- Who's at risk: Any organization running Check Point Security Management or Multi-Domain Management R77.30 through R82.10 with the Management Server reachable from the internet and no Trusted Clients restrictions.
Check Point has shipped emergency fixes for three vulnerabilities in its Security Management and Multi-Domain Security Management (MDSM) products, and one of them is already being used in real attacks. CVE-2026-16232 (CVSS 9.3) is an authentication bypass in the SmartConsole login process that hands an unauthenticated remote attacker an application login token, which they can then replay to authenticate with full administrative privileges. That is not a foothold on an edge device. That is direct control of the console that writes firewall policy for your entire Check Point estate.
Check Point's VP of research, Lotem Finkelstein, confirmed a small number of customers have been targeted and have been notified. The company has not said who is behind the activity, what the post-exploitation objectives were, or when the attacks were first detected. CISA moved quickly regardless: the flaw is now in the Known Exploited Vulnerabilities catalog with a remediation deadline of July 25, 2026 for Federal Civilian Executive Branch agencies. That is a three-day window, which tells you how CISA is reading the risk.
Why a management-plane bypass is worse than a gateway bug
The Management Server is the control plane for every Security Gateway it manages. Per the CVE.org description, successful exploitation lets the attacker modify security policies and security configurations. In practice that means an attacker with an admin token can open pinholes through your perimeter, disable inspection blades, push modified policy to every managed gateway, and create persistence that looks like legitimate administrative change. Firewall audit trails are only as trustworthy as the console that produces them, and this flaw compromises the console itself.
The exploitation preconditions are narrow but common. Remote exploitation requires two things: the Management Server IP is reachable from the internet, and the Trusted Clients (GUI clients) configuration does not restrict which source addresses can connect. Trusted Clients defaults are frequently left wide open in real deployments because admins connect from changing locations, VPN pools, or MSP networks. If your management interface answers to any source IP, you are in the exploitable population.
Check Point released six attacker IP addresses tied to the observed activity: 151.241.99.207, 151.241.99.233, 158.62.198.182, 192.142.10.99, 139.28.37.250, and 194.213.18.137. Search firewall, management API, and SmartConsole authentication logs for connections from these addresses, and treat any hit as a potential full management-plane compromise, not just a scan.
Two more flaws in the same patch batch
CVE-2026-16232 is the headline, but the July 22 release fixes two additional issues that deserve attention. CVE-2026-62144 also carries a CVSS score of 9.3: it is a separate authentication bypass in Security Management and MDSM that lets an unauthenticated remote attacker execute administrative commands on the Management Server, including run-script and exec-command against managed Security Gateways. That is arbitrary command execution on both the management tier and the enforcement tier, gated by the same precondition as the exploited flaw: management access reachable without firewall protection or Trusted Clients restrictions.
CVE-2026-62145 (CVSS 7.5) is an improper privilege management bug in the Gaia Portal. An authenticated user holding read-only Gaia Portal privileges can escalate to command execution as root. On its own it requires credentials, but chained behind either auth bypass, or used by a compromised low-privilege operator account, it converts limited access into full OS control of the management appliance.
Affected versions
All three vulnerabilities affect ten release trains: R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, and R82.10. Note that several of these versions are old enough that many organizations run them on appliances nobody has touched in years. If you inherited a Check Point management box during an acquisition or have a legacy MDSM domain still on R77.30 or R80.x, it is in scope, and those forgotten boxes are exactly the ones most likely to be internet-exposed with default Trusted Clients settings.
What to do now
- Apply the July 22 Jumbo hotfix to all Security Management and MDSM servers on affected versions. This is the only complete fix.
- Restrict Trusted Clients (GUI clients) to specific trusted IP addresses or subnets. This closes the exploitation precondition for both critical CVEs even before patching.
- Get the Management Server off the open internet: place management access behind the firewall and restrict it to trusted source IPs.
- Hunt for the six published IoC IPs across firewall logs, management audit logs, and SmartConsole authentication events going back at least 90 days.
- Review recent policy revisions and administrative changes on the Management Server. Attacker activity here looks like legitimate admin work, so diff current policy against a known-good revision.
- Audit Gaia Portal accounts and rotate credentials for any read-only users, given the CVE-2026-62145 escalation path.
Because this flaw grants full administrative privileges, remediation after a confirmed hit is not just patching. Treat the Management Server as compromised: rotate all administrator credentials and API keys, revoke active sessions, compare deployed gateway policy against the last trusted revision, and rebuild the management appliance if you cannot establish a clean baseline.
The bigger pattern
This is the latest entry in a sustained trend of attackers targeting the management planes of security infrastructure itself: firewalls, VPN concentrators, and the consoles that run them. These systems hold the highest privilege in the network, are frequently exempted from the exposure standards applied to ordinary servers, and often lag on patching because downtime windows are hard to get. The precondition for both critical CVEs here, management exposed directly to the internet without IP restrictions, is a configuration decision, not a vulnerability. Fix the patch gap this week, but fix the exposure permanently. No firewall management interface should be answering to the whole internet in 2026.
Questions about your exposure?
RedEye Security provides assessments for organizations that need to understand their real risk.
Talk to us