TL;DR
Check Point disclosed a SmartConsole authentication bypass on July 22, 2026. The flaw, CVE-2026-16232, is already exploited in the wild against a handful of customers. It carries a CVSS score of 9.3, and a jumbo hotfix is available now.
Why it matters
This authentication bypass hands attackers a way past the login on Check Point Management. CVE-2026-16232 rates 9.3, near the top of the severity scale. The company confirms active abuse, which raises the urgency well beyond a routine patch.
The exposure is narrow, though. Check Point says the attacks hit only “a handful of customers with specific configurations”. The risk appears when Management sits directly on the internet without IP restrictions.
How the attack works
The bug lets an attacker bypass SmartConsole login using an application token. Check Point found it during a routine BLAST review of its own products. As the vendor puts it, “this is exactly why programs like BLAST exist: to find and close gaps before they become real risks.”
The July update also fixes two related flaws. CVE-2026-62144 allows a Management authentication bypass and privilege escalation. CVE-2026-62145 enables local privilege escalation in the GaiaOS WebUI. Neither has been seen exploited.
Affected versions
The flaws hit Security Management and Multi-Domain Management. Affected releases include R81.10, R81.20, R82 and R82.10. Older versions are impacted as well.
Patch and mitigation
Install the jumbo hotfix released on July 22, 2026. Check Point’s official advisory on the active exploitation of CVE-2026-16232 carries the full details and IoCs.
Two steps limit exposure until you patch. First, restrict trusted GUI clients to specific IP addresses. Second, protect Management access behind a firewall and block untrusted networks.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.