All stories
criticalExploited VulnerabilitiesCVE-2026-16232

Attackers bypass Check Point authentication to seize full administrative control of management servers

A critical authentication bypass vulnerability in Check Point's management products is being exploited in the wild. Attackers can obtain a login token to gain full administrative control over security policies and configurations. If your Management Server is exposed directly to the internet without IP restrictions, apply the latest Jumbo hotfix immediately.

Summary

Check Point has confirmed that threat actors are actively exploiting CVE-2026-16232, a critical vulnerability affecting Security Management and Multi-Domain Management products. The flaw allows an unauthenticated remote attacker to bypass authentication by obtaining an application login token, which can then be used via SmartConsole to execute administrative actions.

The vulnerability specifically impacts environments where the Management Server is directly exposed to the internet without IP restrictions on Trusted Clients. While Check Point has noted that the exploitation has affected a very small number of customers, CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on July 22, 2026, with an instruction for federal agencies to remediate by July 25.

Technical details

The vulnerability resides in the SmartConsole login process. An attacker can exploit this flaw to acquire a valid application login token without providing credentials. Once the token is obtained, the attacker gains full administrative privileges, enabling them to modify security policies and change global security configurations.

Successful exploitation requires two specific conditions:

  1. The Management Server IP address must be accessible via the internet.
  2. The configuration must not restrict Trusted Clients (GUI clients) to specific IP addresses or subnets.

In addition to CVE-2026-16232, Check Point's recent security updates also address two other vulnerabilities: CVE-2026-62144 (a critical authentication bypass and privilege escalation flaw) and CVE-2026-62145 (a high-severity local privilege escalation).

Affected products and fixed versions

The vulnerability affects the following Check Point products:

  • Security Management Server
  • Multi-Domain Security Management Server (MDS)

Affected versions include:

Product Versions
Security Management / MDS R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, R82.10

Fixed versions are available via Jumbo Hotfix Accumulators:

  • R82.10: Starting from Take 36
  • R82: Starting from Take 118
  • R81.20: Starting from Take 158

Detection opportunities

To identify potential exploitation attempts, security teams should monitor SmartConsole logs for specific indicators.

Log Search via IP Address Search for events where the source or destination matches these known attacker IPs: 151.241.99.207, 151.241.99.233, 158.62.198.182, 192.142.10.99, 139.28.37.250

You can use the following query in SmartConsole under Logs & Monitor > Logs & Events:

(src:151.241.99.207 OR dst:151.241.99.207 OR src:151.241.99.233 OR dst:151.241.99.233 OR src:158.62.198.182 OR dst:158.62.198.182 OR src:192.142.10.99 OR dst:192.142.10.99 OR src:139.28.37.250 OR dst:139.28.37.250)

Audit Log Monitoring Check the Audit Logs view for entries containing the following string: Authentication method: application token

Defender guidance

Immediate action is required for any management environment exposed to the internet.

1. Apply Patches Install the latest Jumbo hotfix released by Check Point to resolve the underlying vulnerability.

2. Restrict Trusted Clients Configure SmartConsole to ensure that only authorized IP addresses can attempt a login.

  • Navigate to Manage & Settings > Permissions & Administrators > Trusted Clients.
  • Edit your existing client entries and ensure the "Type" is not set to "Any".
  • Explicitly define trusted IP addresses or subnets.

3. Implement Firewall Restrictions Protect Management access using a firewall to restrict access to known, trusted IP addresses. Verify that implied rules for control connections are enabled to prevent unauthorized management access from non-authorized IPs.

Sources

  1. https://www.securityweek.com/new-check-point-zero-day-vulnerability-exploited-in-the-wild/
  2. https://thehackernews.com/2026/07/check-point-patches-exploited.html
  3. https://support.checkpoint.com/results/sk/sk185169
  4. https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/
  5. https://event.on24.com/wcc/r/ 5410205/7BF2B1A3329F74BE93B2AE247EDCDE5B?partnerref=awidget
  6. https://community.checkpoint.com/t5/Firewall-and-Security-Management/CVE-2026-16232-Active-Exploitation-Requires-Immediate-Management/m-p/280065#M106251
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -