CVE-2026-16232 is a critical authentication-bypass flaw in Check Point SmartConsole that carries a CVSS score of 9.3 and has been confirmed as being actively exploited in the wild.
CVE-2026-16232: how the flaw works and what it permits
Check Point has released updates to address CVE-2026-16232, an authentication bypass affecting the SmartConsole login process that "allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges." The vulnerability enables an attacker to take actions with full administrative rights: "Successful exploitation allows the attacker to modify security policies and security configurations," according to the CVE description published on CVE.org.
Lotem Finkelstein, vice president of research at Check Point, said the company is aware of "a small number of customers being targeted by this flaw, and that it has already notified them." He added, "This only affects a very specific configuration - when Management is exposed directly to the internet without IP restrictions." Check Point did not disclose the nature of the attacks or when they were discovered.
Related high-severity bugs addressed alongside CVE-2026-16232
Check Point's July fixes also close two other serious flaws:
- CVE-2026-62144 (CVSS score: 9.3) — described as an authentication bypass in Security Management and Multi-Domain Security Management that "allows an unauthenticated remote attacker to execute administrative commands on the Management Server, including run-script and exec-command on Security Gateway."
- CVE-2026-62145 (CVSS score: 7.5) — an improper privilege management vulnerability in Check Point Gaia Portal that "allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges."
Like CVE-2026-16232, exploitation of CVE-2026-62144 requires management access either without Firewall protection or with no restrictions on Trusted Clients (GUI clients).
Affected Check Point releases and risky configurations
All three issues impact a broad set of Security Management and Multi-Domain Management releases. The vendor lists the following versions as affected:
- R77.30
- R80
- R80.10
- R80.20
- R80.30
- R81
- R81.10
- R81.20
- R82
- R82.10
Check Point specifically warns that the vulnerabilities are tied to management interfaces exposed without proper network protection. The vendor recommends limiting Trusted Clients (GUI clients) to trusted IP addresses/subnets, securing Management access with a Firewall, and restricting access to trusted IP addresses to reduce risk.
Indicators of compromise and confirmation of targeting
Check Point published a short list of network indicators associated with the activity it has observed. The IPv4 addresses listed as indicators of compromise are:
- 151.241.99[.]207
- 151.241.99[.]233
- 158.62.198[.]182
- 192.142.10[.]99
- 139.28.37[.]250
- 194.213.18[.]137
According to Check Point, it has notified a small number of customers identified as targets but "did not disclose the nature of the attacks or when they were discovered."
What this means for security teams, Federal Civilian Executive Branch agencies, and enterprise IT
Security teams should prioritize the July 22 Jumbo hotfix Check Point released and implement the configuration controls the vendor recommends: limit Trusted Clients to trusted IP addresses/subnets, secure Management access behind a Firewall, and restrict access to trusted IPs. These are the specific mitigations Check Point lists alongside the fixes.
Federal Civilian Executive Branch (FCEB) agencies face a hard deadline: the U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog and requires FCEB agencies to apply the necessary fixes by July 25, 2026.
Enterprise IT and procurement leaders that run affected Check Point Management and MDSM versions should inventory exposed management interfaces immediately, apply the July 22 Jumbo hotfix, and evaluate whether any Management Server IP addresses are reachable from the internet without IP restrictions. Check Point's published IoCs provide concrete network addresses for detection efforts.
Check Point's simultaneous disclosure — patches for a high-severity, actively exploited authentication bypass plus two other serious vulnerabilities — and CISA's rapid inclusion of CVE-2026-16232 in the KEV catalog compress the window for defenders. The vendor's guidance and the July 25 FCEB deadline frame a narrow operational timeline: apply the July 22 hotfixes, harden Management access, and hunt for the listed IoCs.




