Ethical Hacking News
A critical security vulnerability has been identified in Check Point products, allowing an unauthenticated remote attacker to gain full administrative access. The vulnerability, tracked as CVE-2026-16232, has been actively exploited in the wild and poses a significant threat to network security. Organizations are advised to apply the necessary patches and implement recommended security measures to minimize the risk of unauthorized access.
A recent security vulnerability (CVE-2026-16232) has been identified, allowing unauthenticated remote attackers to obtain full administrative privileges. The vulnerability has been actively exploited in the wild, with attackers gaining unauthorized access to systems and networks protected by Check Point Security Management products. The flaw allows modification of security policies and configurations, posing a significant threat to network security. Check Point has released security updates to patch the vulnerability and two other flaws, CVE-2026-62144 and CVE-2026-62145. Affected versions include R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, and R82.10. Customers are advised to apply the July 22 Jumbo hotfix, limit Trusted Clients to trusted IP addresses/subnets, secure Management access with Firewall, and restrict access to trusted IP addresses.
A recent security vulnerability has been identified, which has left many organizations concerned about their network and system security. The vulnerability, tracked as CVE-2026-16232, is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
According to a report by The Hacker News, published on July 23, 2026, this critical flaw has been actively exploited in the wild. This means that attackers have already taken advantage of this vulnerability to gain unauthorized access to systems and networks protected by Check Point Security Management and Multi-Domain Management (MDSM) products.
The security flaw allows an attacker to modify security policies and security configurations, which poses a significant threat to network security. To exploit the vulnerability, an attacker requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients.
Lotem Finkelstein, vice president of research at Check Point, stated that the company is aware of a small number of customers being targeted by this flaw and has already notified them. However, it did not disclose the nature of the attacks or when they were discovered.
To address this vulnerability, Check Point has released security updates to patch multiple vulnerabilities impacting Security Management and MDSM products. These patches include those for CVE-2026-16232, which has a CVSS score of 9.3. This indicates that the vulnerability is highly critical and poses a significant risk to network security.
Furthermore, Check Point has also patched two other flaws, CVE-2026-62144 and CVE-2026-62145, which have CVSS scores of 9.3 and 7.5, respectively. The first flaw allows an unauthenticated remote attacker to execute administrative commands on the Management Server, while the second flaw allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.
All affected versions include R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, and R82.10. Customers are recommended to apply the July 22 Jumbo hotfix, limit Trusted Clients (GUI clients) to trusted IP addresses/subnets, secure Management access with Firewall, and restrict access to trusted IP addresses.
The US Cybersecurity and Infrastructure Security Agency (CISA) has also taken notice of this vulnerability and added it to its Known Exploited Vulnerabilities (KEV) catalog. This requires Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by July 25, 2026.
In light of these security concerns, organizations are advised to take immediate action to address this vulnerability. By patching the affected versions and implementing the recommended security measures, they can minimize the risk of unauthorized access and protect their network security.
Related Information:
https://www.ethicalhackingnews.com/articles/Severe-Vulnerability-Exploited-Check-Point-Patches-Flaw-Allowing-Full-Admin-Access-ehn.shtml
https://thehackernews.com/2026/07/check-point-patches-exploited.html
https://blog.gridinsoft.com/check-point-smartconsole-cve-2026-16232/
https://nvd.nist.gov/vuln/detail/CVE-2026-16232
https://www.cvedetails.com/cve/CVE-2026-16232/
https://nvd.nist.gov/vuln/detail/CVE-2026-62144
https://www.cvedetails.com/cve/CVE-2026-62144/
https://nvd.nist.gov/vuln/detail/CVE-2026-62145
https://www.cvedetails.com/cve/CVE-2026-62145/
Published: Thu Jul 23 03:11:08 2026 by llama3.2 3B Q4_K_M