Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild.
Intelligence analysis by Llama

Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232, is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticat…
Imagine you have a super powerful tool that can control everything in your house. But, someone found a way to get into the tool without a password, and now they can control everything. That's what happened with Check Point's SmartConsole. A bad guy found a way to get into the tool without a password, and now they can control everything. Check Point fixed the problem, but people need to update their tool to be safe.
Analysis
A Critical Flaw in Check Point's SmartConsole
Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232, is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
According to Check Point, the vulnerability only affects a very specific configuration - when Management is exposed directly to the internet without IP restrictions. The company has shared the below indicators of compromise (IoCs) associated with the activity - 151.241.99[.]207, 151.241.99[.]233, 158.62.198[.]182, 192.142.10[.]99, 139.28.37[.]250, and 194.213.18[.]137.
Patches have also been released for two other flaws - CVE-2026-62144 and CVE-2026-62145. CVE-2026-62144 is an authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management that allows an unauthenticated remote attacker to execute administrative commands on the Management Server, including run-script and exec-command on Security Gateway. CVE-2026-62145 is an improper privilege management vulnerability in Check Point Gaia Portal that allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.
All three issues impact the following versions - R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, and R82.10. Customers are recommended to apply the July 22 Jumbo hotfix, limit Trusted Clients (GUI clients) to trusted IP addresses/subnets, secure Management access with Firewall, and restrict access to trusted IP addresses.
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by July 25, 2026.
Key points
- Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products.
- The security flaw, tracked as CVE-2026-16232, is an authentication bypass affecting the Check Point SmartConsole login process.
- Patches have also been released for two other flaws - CVE-2026-62144 and CVE-2026-62145.
- Customers are recommended to apply the July 22 Jumbo hotfix, limit Trusted Clients (GUI clients) to trusted IP addresses/subnets, secure Management access with Firewall, and restrict access to trusted IP addresses.
Check Point's prompt response to the vulnerability and release of patches demonstrate their commitment to securing their products and protecting their customers. This proactive approach will help mitigate the impact of the vulnerability and prevent further exploitation.
The fact that the vulnerability has been actively exploited in the wild highlights the importance of timely patching and vulnerability management. If customers fail to apply the necessary fixes, they may be left exposed to attacks, which could have severe consequences.



