Check Point SmartConsole CVE-2026-16232: Admin Bypass

Check Point SmartConsole CVE-2026-16232 is now on CISA’s Known Exploited Vulnerabilities list: an unauthenticated attacker can forge a login token and get full administrator access to the console that manages an organization’s entire firewall fleet. Check Point patched it on July 22 and confirmed a handful of customers were already targeted. The federal remediation deadline was July 25 — already passed for anyone reading this on Monday.
What Happened
Check Point SmartConsole CVE-2026-16232 (CVSS 9.3 per CVE.org, reported as 9.1 by some outlets) is an authentication bypass in the SmartConsole login process affecting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) deployments. An unauthenticated remote attacker obtains an application login token during login and uses it to authenticate with full administrative privileges — no username, password, or MFA involved. Once inside, the attacker can read and rewrite security policy and configuration across every gateway that management server controls.
Exploitation depends on one specific, common misconfiguration: the Management Server IP reachable from the internet with no restriction on Trusted Clients (GUI clients). Check Point’s VP of Research, Lotem Finkelstein, said the flaw surfaced during a routine internal review and that a “handful of customers” were confirmed targeted; Smart-1 Cloud customers were unaffected and all identified victims were notified directly. Check Point patched two related flaws the same day: CVE-2026-62144 (CVSS 9.3, auth bypass enabling arbitrary admin command execution, including run-script and exec-command on managed gateways) and CVE-2026-62145 (CVSS 7.5, local privilege escalation to root via the Gaia Portal). All three affect essentially every currently supported version line — R77.30, R80.x, R81.x, and R82.x.
CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog on July 22, 2026, giving U.S. federal agencies until July 25 to remediate under Binding Operational Directive 26-04. Check Point published five indicator-of-compromise IP addresses and a SmartConsole audit-log query administrators can run to check for prior compromise.
Why It Matters
This is the second Check Point CVE with confirmed active exploitation in six weeks. DIESEC covered CVE-2026-50751 on June 10 — an IKEv1 VPN authentication bypass exploited by the Qilin ransomware gang. Now the management console itself, not the VPN gateway, is the entry point. For DACH Mittelstand IT teams and for MSPs running multiple client firewall fleets from a single SmartConsole or Multi-Domain instance, that distinction matters: a stolen token doesn’t compromise one firewall, it compromises every gateway that console manages.
CISA’s bulletin also references a 2024 Check Point Quantum Gateway CVE exploited by NailaoLocker ransomware — the third Check Point flaw with confirmed exploitation in roughly two years, and the second in a single summer. Patch cadence alone does not close this gap; the underlying exposure — management interfaces reachable from the internet — is an architecture decision, not a version number.
What You Should Do Now
- Apply the July 22 Jumbo Hotfix to every Security Management Server and Multi-Domain Security Management Server immediately, regardless of version (R77.30 through R82.10 are all affected).
- Check whether your Management Server IP is reachable from the internet. If it is, and Trusted Clients (GUI clients) are not restricted to specific IPs or subnets, treat that instance as exposed until confirmed otherwise.
- If you cannot patch immediately, restrict Trusted Clients to known management IPs and put the Management Server behind a firewall that blocks access from non-authorized addresses — Check Point’s own Gateway and Management Hardening Best Practices Guide covers the exact steps.
- Run the SmartConsole audit-log query for “Authentication method: application token” under Logs & Monitor and cross-check traffic against Check Point’s published indicators of compromise (five IP addresses; see the source advisory) to rule out prior compromise before assuming the patch alone closed the incident.
If you manage firewalls for multiple clients from one console — an MSP model common across DACH IT service providers — audit which of those clients’ gateways were reachable through this exposure before the July 22 patch, not just whether the patch is now applied.
DIESEC Perspective
This is a pattern we see repeatedly in Mittelstand and MSP environments: the firewall gets hardened, monitored, and patched on schedule, while the console that administers it quietly keeps a wide-open management interface because “it’s only used internally” — until it isn’t. Two Check Point trust boundaries broken in one summer, one at the perimeter and one at the management plane, is a reminder that exposure architecture needs the same review cadence as patch management.
Not sure whether your firewall management console has this exposure? Contact DIESEC for a rapid firewall management exposure and access-control review.
Sources: BleepingComputer | The Hacker News
Published: 2026-07-27 | Category: Vulnerabilities & Patches | ~4 min read

