Summary

Check Point disclosed a critical zero-day authentication bypass in its SmartConsole, Security Management, and Multi-Domain Management (MDSM) products, tracked as CVE-2026-16232 (CVSS 9.3). The flaw lets an unauthenticated remote attacker obtain a login token and gain full administrative control of the management server — no credentials required. Affected versions span R77.30 through R82.10.

Exploitation requires the Management Server to be internet-accessible with Trusted Clients set to “Any” — a common misconfiguration. Check Point released a Jumbo Hotfix on July 22, 2026 and confirmed active exploitation against a limited number of customers. The July 2026 update also patches two additional flaws: CVE-2026-62144 (auth bypass + privilege escalation, CVSS 9.3) and CVE-2026-62145 (local privilege escalation in Gaia Portal, CVSS 7.5) — both not yet exploited.

CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) catalog on July 22, mandating federal remediation by July 25, 2026. Known attacker IPs: 151.241.99[.]207, 151.241.99[.]233, 158.62.198[.]182, 192.142.10[.]99, 139.28.37[.]250, 194.213.18[.]137.

Source

Check Point Security Advisory
BleepingComputer
The Hacker News
CISA KEV Catalog

Commentary

An unauthenticated attacker walking into your firewall management console with a stolen token is as bad as it gets for network security infrastructure. The attack surface is self-inflicted: management ports exposed to the internet with Trusted Clients set to “Any” is a misconfiguration that has no business existing in 2026.

Patch immediately — July 25 is not a suggestion. Check SmartConsole logs against the provided IOC IPs, restrict management access to named IP ranges, and audit all admin accounts for unauthorized activity. Active exploitation confirmed before the hotfix dropped means some orgs are already compromised. Rotate credentials on any internet-exposed management server regardless of patch status.

By Allan