Ethical Hacking News
Check Point has patched a critical authentication bypass flaw in its SmartConsole that has been actively exploited by threat actors. The vulnerability allows unauthenticated remote attackers to obtain a SmartConsole login token and gain full administrative access, highlighting the importance of regular security patching and proactive measures to prevent exploitation.
Check Point has patched a critical authentication bypass flaw (CVE-2026-16232) in their SmartConsole, rated at CVSS score of 9.3. The vulnerability allows unauthenticated remote attackers to obtain a login token and gain full administrative access. Restricting SmartConsole Trusted Clients to trusted IP addresses only and protecting Management Server access with firewall rules are recommended mitigation measures. Regularly reviewing security patches is crucial, and the patch has already been made available for immediate application. Two additional vulnerabilities (CVE-2026-62144 and CVE-2026-62145) have also been patched, impacting the Gaia Portal with escalated privileges and command execution.
Recent security patches have been made available for Check Point's SmartConsole to address a critical authentication bypass flaw that has been actively exploited by threat actors, according to the latest update from Security Affairs.
The identified vulnerability, tracked as CVE-2026-16232, is rated at a high CVSS score of 9.3 and is impacting various products and versions of Check Point's security management solutions. This critical flaw allows unauthenticated remote attackers to obtain a SmartConsole login token and gain full administrative access to the system.
The successful exploitation of this vulnerability requires no restrictions on Trusted Clients (GUI clients) and internet access to the Management Server IP address. The attacker IP addresses that have been identified as indicators of compromise (IoCs) are 151.241.99[.]207, 151.241.99[.]233, 158.62.198[.]182, 192.142.10[.]99, 139.28.37[.]250, and 194.213.18[.]137.
To mitigate the attack, Check Point has advised administrators to restrict SmartConsole Trusted Clients to trusted IP addresses only (avoid using "Any") and protect Management Server access with firewall rules. They should also review logs for connections involving known attacker IP addresses to detect potential compromise.
This vulnerability highlights the importance of regularly reviewing security patches and taking proactive measures to prevent exploitation by threat actors. The patch has already been made available, and it is recommended that administrators apply it as soon as possible.
Furthermore, Check Point has patched two additional vulnerabilities: CVE-2026-62144 (CVSS score of 9.3) and CVE-2026-62145 (CVSS score of 7.5). These vulnerabilities impact the Gaia Portal and allow authenticated users with read-only access to escalate privileges and execute commands as root.
Customers should install the July 22 Jumbo hotfix, restrict Trusted Clients to approved IP addresses or subnets, and protect Management access through firewall rules allowing only authorized sources.
In light of this critical security update, it is essential for organizations using Check Point's SmartConsole to take immediate action to patch this vulnerability and implement robust security measures to prevent potential exploitation by threat actors.
Related Information:
https://www.ethicalhackingnews.com/articles/Check-Point-Patches-Critical-Authentication-Bypass-Flaw-Exploited-by-Threat-Actors-ehn.shtml
https://securityaffairs.com/195848/hacking/check-point-patches-actively-exploited-smartconsole-authentication-bypass-flaw.html
https://nvd.nist.gov/vuln/detail/CVE-2026-16232
https://www.cvedetails.com/cve/CVE-2026-16232/
https://nvd.nist.gov/vuln/detail/CVE-2026-62144
https://www.cvedetails.com/cve/CVE-2026-62144/
https://nvd.nist.gov/vuln/detail/CVE-2026-62145
https://www.cvedetails.com/cve/CVE-2026-62145/
Published: Thu Jul 23 05:41:55 2026 by llama3.2 3B Q4_K_M