CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◆ Security Tools & Reviews Jul 23, 2026

CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild

Rapid7 Archived Jul 23, 2026 ✓ Full text saved

Overview On July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232 , an authentication bypass in the SmartConsole login process classified as improper authentication ( CWE-287 ). CVE-2026-16232 has been assigned a critical CVSS score of 9.1. The vulnerability allows an unauthenticated remote attacker to obtain an application login token and auth

Full text archived locally
✦ AI Summary · Claude Sonnet


    OverviewOn July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232, an authentication bypass in the SmartConsole login process classified as improper authentication (CWE-287). CVE-2026-16232 has been assigned a critical CVSS score of 9.1. The vulnerability allows an unauthenticated remote attacker to obtain an application login token and authenticate to the management server with full administrative privileges, enabling modification of security policies and configurations.Check Point has confirmed that CVE-2026-16232 is being actively exploited in the wild, affecting what the vendor describes as a small number of customers. Remote exploitation requires network access to the Management Server IP address in environments that do not restrict Trusted Clients. On the same day as the advisory, CVE-2026-16232 was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) list of known exploited vulnerabilities (KEV), with a remediation due date of July 25, 2026, giving organizations only three days to respond.The advisory addresses three vulnerabilities in total:CVECVSSDescriptionAffected ProductsExploitation StatusCVE-2026-16232Vendor: 9.3 (Critical)CISA: 9.1 (Critical)Authentication bypass via SmartConsole application tokenSecurity Management, Multi-Domain ManagementExploited in the wildCVE-2026-62144Vendor: 9.3 (Critical)CISA: 9.1 (Critical)Management authentication bypass and privilege escalationSecurity Management, Multi-Domain ManagementNo known exploitationCVE-2026-621457.5 (High)Local privilege escalation in GaiaOS WebUIFirewall, Multi-Domain Management, Multi-Domain Log ServerNo known exploitationCompromise of a Security Management Server is particularly consequential because it sits at the top of the trust hierarchy. An attacker with administrative access can modify security policies across managed gateways, alter administrator permissions, manipulate VPN configurations, and potentially disable or tamper with logging and monitoring. According to Check Point's advisory, the vulnerabilities were discovered during a routine internal review, with subsequent analysis revealing that CVE-2026-16232 had been exploited prior to the availability of a patch.Check Point network security products have been targeted by multiple in-the-wild vulnerabilities over the past two years. In June 2026, CVE-2026-50751, a critical authentication bypass in Check Point Remote Access VPN, was exploited in the wild and added to the CISA KEV. In May 2024, CVE-2024-24919, a high-severity information disclosure vulnerability in Check Point Quantum Security Gateways, was also exploited in the wild. Organizations running affected Check Point management products should apply the available hotfixes on an emergency basis.Mitigation guidanceCheck Point released Jumbo Hotfixes on July 22, 2026, to remediate CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145. Organizations running affected versions of Security Management or Multi-Domain Management should install the latest Jumbo Hotfix on an emergency basis, without waiting for a regular patch cycle to occur.The following versions are affected by CVE-2026-16232:R82.10: fixed in Jumbo Hotfix Take 36 and laterR82: fixed in Jumbo Hotfix Take 118 and laterR81.20: fixed in Jumbo Hotfix Take 158 and laterR81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30: no fix specifiedCVE-2026-62144 and CVE-2026-62145 affect the same release families (R81.10, R81.20, R82, R82.10) per the vendor advisory, with older versions also impacted.Smart-1 Cloud customers are already protected according to Check Point. For on-premises deployments where the hotfix cannot be applied immediately, Check Point recommends the following steps to reduce exposure:Restrict Trusted Clients (GUI clients) to trusted IP addresses or subnetsProtect Management access with a firewall and restrict access to trusted IP addressesVerify that implied rules for control connections are enabledThese mitigations reduce the attack surface, but they do not address the underlying vulnerability. Installing the Jumbo Hotfix remains the priority.Rapid7 strongly recommends investigating for signs of compromise even after applying the hotfix, particularly in environments where the Management Server has been accessible from the internet. Organizations should review administrator, SmartConsole, API, and application token activity, and search logs for the published indicators of compromise listed below.For the latest mitigation guidance, please refer to the vendor advisory.Rapid7 customersExposure Command, InsightVM, and NexposeExposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-16232, CVE-2026-62144, CVE-2026-62145 with authenticated vulnerability checks expected to be available in the 24 July content release.Indicators of compromiseCheck Point has published the following IP addresses associated with observed exploitation of CVE-2026-16232:151.241.99[.]207151.241.99[.]233158.62.198[.]182192.142.10[.]99139.28.37[.]250194.213.18[.]137Per the vendor, the presence of these indicators should prompt investigation, but the absence of these addresses does not confirm that an environment was unaffected.UpdatesJuly 23, 2026: Initial publication.Article TagsEmergent Threat ResponseLabsVulnerability ManagementRapid7Author PostsRelated blog postsVulnerabilities and ExploitsCVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress CoreRapid7 LabsVulnerabilities and ExploitsCVE-2026-58644: Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the WildRapid7Vulnerabilities and ExploitsRapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)Rapid7Vulnerabilities and ExploitsActive Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)Jonah BurgessSee all posts
    💬 Team Notes
    Article Info
    Source
    Rapid7
    Category
    ◆ Security Tools & Reviews
    Published
    Jul 23, 2026
    Archived
    Jul 23, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗