At a glance:
-
Check Point disclosed active exploitation of an authentication bypass vulnerability that allows an unauthenticated threat actor to gain full administrative access to affected management systems.
-
The vulnerability was exploited against internet-accessible deployments that did not restrict administrative access to trusted networks.
-
The flaw allows a threat actor to authenticate with full administrative privileges, providing administrative access to the security management platform.
Threat summary
On July 22, 2026, Check Point released several security updates for its firewall and management products and disclosed active exploitation of a critical authentication bypass vulnerability affecting Security Management Server and Multi-Domain Security Management Server.
Check Point reported that a small number of customers were targeted. The vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on July 22.
Check Point Security Management provides centralized administration of security policies, administrators, logging, Virtual Private Networks (VPNs), and security gateways.
The vulnerability, tracked as CVE-2026-16232, is an authentication bypass in the SmartConsole login process. Administrators use SmartConsole to connect to Security Management servers and manage the environment.
The flaw allows an unauthenticated threat actor to obtain an application login token and use it to authenticate through SmartConsole with full administrative privileges. Successful exploitation allows an adversary to modify security policies and security configurations.
The vulnerability was rated with a Common Vulnerability Scoring System (CVSS) score of 9.3.
According to Check Point, successful exploitation requires both of the following conditions:
- The Security Management Server is accessible from the internet.
- "Trusted Clients" are not restricted to approved administrator IP addresses or subnets. In this deployment scenario, a threat actor can connect directly to the vulnerable SmartConsole login process and attempt exploitation.
Check Point notified affected customers, and noted that all Smart-1 Cloud customers were already protected.
Recommendations
Security Management servers act as the administrative control plane for a Check Point environment. They are used to centrally manage firewall policies, administrator accounts, gateway configuration, logging, Virtual Private Network (VPN) settings, and other security controls. Access obtained through CVE-2026-16232 provides the same level of authority available to a legitimate Check Point administrator.
According to Check Point, successful exploitation allows modification of security policies and security configurations. Based on the functions managed by the platform, a threat actor may also be able to modify firewall policies, change administrator settings, alter VPN configurations, and adjust other centrally managed security controls.
Check Point released fixes for CVE-2026-16232 on July 22, as part of its Jumbo Hotfix release. Recommended actions include restricting Trusted Clients to approved IP addresses and subnets, limiting management access to trusted networks, protecting management systems with firewall controls, and reviewing logs for the indicators of compromise published by the vendor.