Open Nav
Sign Up

Check Point SmartConsole Authentication Bypass (CVE-2026-16232)

checkpoint_cve-2026-16232

Filip Dimitrov

July 24, 2026

Check Point has released an urgent security update addressing three vulnerabilities affecting its Security Management, Multi-Domain Management, Quantum Security Gateway, and Gaia operating system products.

The most serious vulnerability, tracked as CVE-2026-16232, enables an unauthenticated remote attacker to bypass the SmartConsole login process and obtain full administrative access to an exposed Check Point Management Server. Check Point has confirmed that the vulnerability was exploited against a small number of customers before patches became available.

Key Findings

  • CVE-2026-16232 is under active exploitation.
  • Successful exploitation can provide an unauthenticated attacker with full SmartConsole administrative privileges.
  • Exploitation requires network access to the Management Server and a configuration that does not adequately restrict Trusted Clients.
  • Attackers may be able to modify firewall policies, security configurations, administrators, managed objects, and gateway settings.
  • Check Point also patched two related vulnerabilities: CVE-2026-62144 and CVE-2026-62145.
  • CISA has added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog.
  • Check Point has released six IP addresses associated with observed exploitation.

Vulnerability Overview

CVESeverityVulnerabilityExploitation status
CVE-2026-16232Critical – 9.3SmartConsole authentication bypass resulting in full administrative accessExploited in the wild
CVE-2026-62144Critical – 9.3Management authentication bypass allowing administrative command executionNo exploitation reported
CVE-2026-62145High – 7.5Gaia Portal privilege escalation from read-only access to rootNo exploitation reported

Check Point discovered the vulnerabilities during an internal security review. The company subsequently determined that CVE-2026-16232 had already been used against several customers whose Management Servers were directly accessible from the internet without IP-based restrictions.

CVE-2026-16232: SmartConsole Authentication Bypass

CVE-2026-16232 is an authentication bypass vulnerability in the Check Point SmartConsole login process.

An unauthenticated attacker who can reach a vulnerable Management Server may obtain an application login token and use it to authenticate through SmartConsole with full administrative privileges. No legitimate username, password, or existing authenticated session is required.

Successful exploitation can allow an attacker to modify security policies and management configurations. Because the Management Server controls security gateways and centrally administered firewall policies, compromise of this system could have consequences extending beyond the server itself.

An attacker with administrative access could potentially:

  • Modify firewall and network access policies
  • Create or alter administrator accounts
  • Add malicious rules or weaken existing protections
  • Change network objects and gateway configurations
  • Enable unauthorized connectivity into protected environments
  • Interfere with logging, monitoring, or incident investigation
  • Establish persistent administrative access
  • Use altered policies to support lateral movement or data exfiltration

Remote exploitation is possible when the attacker can connect to the Management Server IP address and the environment does not restrict SmartConsole Trusted Clients to approved IP addresses or networks.

This exposure condition is important: the vulnerability does not mean every Check Point deployment is immediately exploitable from the internet. However, organizations should not assume they are safe without verifying their actual management-plane exposure and Trusted Clients configuration.

CVE-2026-62144: Management Command Execution

CVE-2026-62144 is a separate authentication bypass vulnerability affecting Check Point Security Management and Multi-Domain Security Management.

An unauthenticated remote attacker with access to the Management Server may execute administrative commands without valid credentials. The available actions can include commands such as run-script and exec-command, potentially extending execution from the Management Server to managed Security Gateways.

Like CVE-2026-16232, exploitation depends on the attacker having network access to an insufficiently protected Management Server or an environment in which Trusted Clients have not been appropriately restricted.

Check Point has not reported active exploitation of CVE-2026-62144. Nevertheless, the vulnerability should be treated as critical because it can provide an unauthenticated attacker with administrative command execution across centrally managed security infrastructure.

CVE-2026-62145: Gaia Portal Privilege Escalation

CVE-2026-62145 is an improper privilege management vulnerability in the Check Point Gaia Portal.

An attacker who already possesses a valid account with read-only Gaia Portal privileges may exploit the flaw to execute commands with root privileges. The vulnerability requires authentication, but successful exploitation provides the attacker with the highest level of operating-system access.

Root-level access may enable an attacker to alter system configurations, access sensitive information, disable controls, install persistent tooling, or interfere with the integrity and availability of the affected system.

Check Point has not reported exploitation of CVE-2026-62145 in the wild.

Affected Products and Versions

The vulnerabilities affect Check Point products across multiple supported and legacy release branches.

Affected versions include:

  • R77.30
  • R80
  • R80.10
  • R80.20
  • R80.30
  • R81
  • R81.10
  • R81.20
  • R82
  • R82.10

The specific products affected vary by vulnerability:

  • CVE-2026-16232: Security Management and Multi-Domain Management
  • CVE-2026-62144: Security Management and Multi-Domain Security Management
  • CVE-2026-62145: Quantum Security Gateway, Security Management, Multi-Domain Management, and related Gaia Portal deployments

Check Point’s advisory lists R81.10, R81.20, R82, and R82.10 as the principal affected release branches while noting that older versions are also impacted. The corresponding Jumbo Hotfix documentation confirms that fixes have been incorporated into updated hotfix takes for supported versions.

Organizations should consult Check Point’s SecureKnowledge articles for the exact fixed Jumbo Hotfix take applicable to each installed version rather than relying solely on the major release number.

Active Exploitation

Check Point confirmed that CVE-2026-16232 was exploited against a handful of customers operating Management Servers exposed directly to the internet without IP restrictions.

The vendor has not publicly disclosed the identity, motivation, or origin of the threat actor, nor has it described the complete post-exploitation activity observed in compromised environments. It is therefore not currently possible to attribute the attacks to a specific campaign or intrusion set.

CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog on July 22, 2026, based on evidence of active exploitation. U.S. Federal Civilian Executive Branch agencies were directed to remediate the vulnerability by July 25, 2026.

The unusually short remediation deadline reflects the severity of a remotely exploitable authentication bypass affecting the centralized management plane of enterprise security infrastructure.

Indicators of Compromise

Check Point published the following source IP addresses associated with observed exploitation:

151.241.99[.]207

151.241.99[.]233

158.62.198[.]182

192.142.10[.]99

139.28.37[.]250

194.213.18[.]137

Organizations should search Check Point management, firewall, VPN, authentication, endpoint, SIEM, and network telemetry for connections involving these addresses.

The IP addresses should not be treated as complete or permanent detection coverage. Attackers may change infrastructure, route traffic through proxies, or use previously compromised systems. Their absence from logs does not prove that a system was not targeted or compromised.

Mitigation and Remediation

Check Point customers should take the following actions immediately:

  1. Install the July 22, 2026 Jumbo Hotfix
    Apply the latest supported Jumbo Hotfix containing fixes for CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145. Confirm that installation completed successfully and that the running hotfix take is newer than the affected version documented by Check Point.
  2. Restrict Trusted Clients
    Configure Trusted Clients so that SmartConsole and other management connections are accepted only from authorized administrative IP addresses or tightly controlled management subnets.
  3. Remove direct internet exposure
    Do not expose Check Point Management Servers or Gaia Portal interfaces directly to the public internet. Place management services behind appropriate firewall rules, private management networks, or secure administrative access controls.
  4. Verify control-connection protections
    Confirm that implied rules for Check Point control connections are enabled and that management access is protected by firewall policy.
  5. Review administrative activity
    Investigate recent administrator sessions, application tokens, account changes, command execution, policy modifications, and gateway configuration changes.
  6. Rotate potentially exposed credentials and tokens
    Where compromise is suspected, revoke application tokens, reset administrative credentials, review API users, and invalidate unauthorized sessions.

Stay Safe. Stay Secure

OP Innovate Research Team

Under Cyber Attack?

Fill out the form and we will contact you immediately.