Full Report
Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an
Analysis Summary
# Vulnerability: Check Point SmartConsole Authentication Bypass
## CVE Details
- **CVE ID:** CVE-2026-16232
- **CVSS Score:** 9.3 (Critical)
- **CWE:** Authentication Bypass (Specific CWE not listed in text)
## Affected Systems
- **Products:** Check Point Security Management and Multi-Domain Management (MDSM) products.
- **Versions:** R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, R82.10.
- **Configurations:** Systems where the Management Server is directly exposed to the internet and "Trusted Clients" (GUI clients) restrictions are not configured.
## Vulnerability Description
A critical authentication bypass exists in the SmartConsole login process. An unauthenticated remote attacker can obtain an application login token, which can then be used to authenticate with full administrative privileges. This allows the attacker to modify security policies and system configurations.
## Exploitation
- **Status:** Actively exploited in the wild (Confirmed by CISA and Check Point).
- **Complexity:** Low (Requires only internet access to the Management Server IP without IP restrictions).
- **Attack Vector:** Network.
## Impact
- **Confidentiality:** High (Full administrative access to security management).
- **Integrity:** High (Ability to modify security policies and configurations).
- **Availability:** High (Potential to disrupt security gateway operations).
## Remediation
### Patches
- Apply the **July 22 Jumbo Hotfix** released by Check Point for all affected versions.
### Workarounds
- **Restrict Trusted Clients:** Limit the "Trusted Clients" (GUI clients) setting to specific, authorized IP addresses or subnets only.
- **Network Hardening:** Ensure Management access is secured behind a firewall and not directly exposed to the public internet.
## Detection
### Indicators of Compromise (IoCs)
The following IP addresses have been associated with exploitation activity:
- 151.241.99[.]207
- 151.241.99[.]233
- 158.62.198[.]182
- 192.142.10[.]99
- 139.28.37[.]250
- 194.213.18[.]137
### Detection Methods
- Review Management Server logs for unauthorized login tokens or unexpected administrative sessions.
- Monitor for unauthorized changes to security policies or gateway configurations.
## References
- Vendor Advisory: hxxps[://]blog[.]checkpoint[.]com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/
- Check Point Support (SK): hxxps[://]support[.]checkpoint[.]com/results/sk/sk185169/
- CISA KEV Catalog: hxxps[://]www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog