Check Point patches actively exploited SmartConsole authentication bypass flaw

Check Point addressed a critical authentication bypass flaw, tracked as CVE-2026-16232, in SmartConsole that is being actively exploited.
Check Point has released security updates to fix multiple vulnerabilities, including CVE-2026-16232 (CVSS score of 9.3), a critical authentication bypass flaw affecting Security Management and Multi-Domain Management (MDSM).
The vulnerability, which is under active exploitation, allows unauthenticated remote attackers to obtain a SmartConsole login token and gain full administrative access.
“An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration. Check Point is aware that this vulnerability is being exploited, impacting a very small number of customers.” reads the advisory. “Successful remote exploit requires internet access to the Management Server IP address and no restrictions on Trusted Clients (GUI clients).”
Successful exploitation requires the Management Server to be accessible from the internet and Trusted Clients (GUI client) access restrictions to be disabled.
Check Point said it is aware of a limited number of customers targeted through CVE-2026-16232 and has already notified the affected organizations. The following attacker IP addresses have been identified as indicators of compromise (IoCs):
- 151.241.99[.]207
- 151.241.99[.]233
- 158.62.198[.]182
- 192.142.10[.]99
- 139.28.37[.]250
- 194.213.18[.]137
The flaw impacts the following products and versions:
- Products: Security Management Server, Multi-Domain Security Management Server (MDS)
- Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81 R81.10, R81.20, R82, R82.10
To mitigate the attack, restrict SmartConsole Trusted Clients to trusted IP addresses only (avoid using “Any”), protect Management Server access with firewall rules, and ensure implied control connection rules are enabled. Administrators should also review logs for connections involving known attacker IP addresses to detect potential compromise.
Check Point also addressed two additional security vulnerabilities:
- CVE-2026-62144 (CVSS score of 9.3): A critical authentication bypass flaw in Security Management and Multi-Domain Security Management that enables unauthenticated remote attackers to execute administrative actions on the Management Server, including
run-scriptandexec-commandoperations on Security Gateways. - CVE-2026-62145 (CVSS score of 7.5): An improper privilege management issue in the Gaia Portal that allows authenticated users with read-only access to escalate privileges and execute commands as root.
Customers should install the July 22 Jumbo hotfix, restrict Trusted Clients to approved IP addresses or subnets, and protect Management access through firewall rules allowing only authorized sources.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Check Point)
Click Here For The Original Source.
