BusinessCybersecurityNewswireTechnologyWhat's Buzzing

Attackers Exploit Critical Check Point Bug to Hijack Firewall Mgmt

▼ Summary

– Attackers are exploiting CVE-2026-16232, an authentication bypass in Check Point Security Management and Multi-Domain Security Management, allowing unauthenticated attackers to gain full admin access via SmartConsole.
– Hotfixes are available for supported versions (R81.20, R82, R82.10); mitigation includes restricting Trusted Clients to trusted IP addresses and protecting Management access with a firewall.
– The vulnerability requires internet access to the Management Server IP address and no restrictions on GUI clients; Check Point has shared attack-related IP addresses for verification.
– CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog, requiring US federal agencies to remediate by July 25 and investigate potential compromise.
– Additional critical flaws fixed include CVE-2026-62144 (allowing unauthenticated command execution) and CVE-2026-62145 (allowing authenticated read-only users to run commands as root), though these are not actively exploited.

Attackers are actively exploiting a critical authentication bypass vulnerability in Check Point security appliances, specifically targeting the Security Management and Multi-Domain Security Management servers. These management systems are responsible for pushing policy configurations to Check Point firewalls and security gateways.

The vulnerability, tracked as CVE-2026-16232, allows an unauthenticated attacker to generate an application login token. Once obtained, this token can be used to log into SmartConsole with full administrative privileges. “An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration,” the company stated.

Check Point confirmed that exploitation is already occurring in the wild. A “handful” of customers have been affected and have received direct notification.

Remediation, Mitigation, and Investigation

CVE-2026-16232 impacts both supported and end-of-service versions of Check Point Security Management and Multi-Domain Security Management. Hotfixes are now available for the supported versions: R81.20, R82, and R82.10.

The company noted that a successful remote exploit requires internet access to the Management Server IP address and no restrictions on Trusted Clients (GUI clients). Therefore, if immediate patching via the provided jumbo hotfixes is not possible, organizations can reduce their risk by limiting Trusted Clients to specific, trusted IP addresses or subnets. Additionally, protecting Management access with a firewall and restricting access to only trusted IP addresses provides another layer of defense.

Check Point has also released a list of IP addresses associated with the ongoing attacks. Customers are instructed to use this data to verify if their systems have been compromised.

A prominent contributor to Check Point’s CheckMates community forum emphasized the severity of the situation. “The Management Server is not simply another administrative system. It controls critical security functions such as: security policies, administrator permissions, managed gateways, VPN configurations, Threat Prevention settings, policy installation, logging and monitoring,” the contributor wrote. “A vulnerability affecting the Management Plane can undermine the trust model of the entire security architecture. Even organizations whose Management Servers are not directly exposed to the Internet should not postpone remediation. Network restrictions reduce exposure, but they do not remove the vulnerable code.”

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog. Civilian US federal agencies are required to address the flaw by July 25 and investigate whether they have been targeted by attackers.

Additional Flaws Fixed

The same jumbo hotfixes released by Check Point also address two other vulnerabilities:

  • CVE-2026-62144: A similarly critical flaw that allows unauthenticated attackers to execute administrative commands on the Management Server. This can then be leveraged to run commands on managed security gateways.Neither of these additional vulnerabilities is known to be actively exploited at this time. However, CVE-2026-62145 also affects Check Point firewalls (excluding Check Point Spark Gateways), not just the management servers.
(Source: Help Net Security)

Topics

authentication bypass 98% check point vulnerability 95% active exploitation 93% remote exploitation 92% security management server 90% remediation hotfixes 88% critical severity 87% Mitigation Strategies 86% unauthenticated attack 85% threat investigation 84%