Check Point Fixes Critical SmartConsole Flaw Exploited in the Wild

Check Point has released security updates to address multiple vulnerabilities in its Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has been actively exploited.

The most severe of these vulnerabilities, identified as CVE-2026-16232 with a CVSS score of 9.3, is an authentication bypass in the SmartConsole login process. This flaw allows an unauthenticated remote attacker to obtain an application login token, granting full administrative privileges. Exploiting this vulnerability enables attackers to modify security policies and configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients.

Lotem Finkelstein, vice president of research at Check Point, stated that the company is aware of a small number of customers targeted by this flaw and has notified them accordingly. He emphasized that the issue affects a specific configuration where the Management Server is exposed directly to the internet without IP restrictions.

Check Point has provided indicators of compromise (IoCs) associated with this activity, including specific IP addresses. Additionally, patches have been released for two other vulnerabilities:

  • CVE-2026-62144 (CVSS score: 9.3): An authentication bypass in Security Management and MDSM that allows an unauthenticated remote attacker to execute administrative commands on the Management Server, including running scripts and executing commands on the Security Gateway.
  • CVE-2026-62145 (CVSS score: 7.5): An improper privilege management issue in the Gaia Portal that permits an authenticated attacker with read-only privileges to execute commands with root privileges.

Exploitation of CVE-2026-62144 requires management access without firewall protection or unrestricted Trusted Clients (GUI clients). All three vulnerabilities affect the following versions:

  • R77.30
  • R80
  • R80.10
  • R80.20
  • R80.30
  • R81
  • R81.10
  • R81.20
  • R82
  • R82.10

Customers are advised to apply the July 22 Jumbo hotfix, limit Trusted Clients to specific IP addresses or subnets, secure Management access with a firewall, and restrict access to trusted IP addresses.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by July 25, 2026.

This incident underscores the critical importance of promptly addressing vulnerabilities in security management systems. Organizations should not only apply patches swiftly but also review and strengthen their access controls to prevent unauthorized access. Regular audits and adherence to best practices in network security are essential to mitigate such risks.