Published on July 23, 2026

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)


Severity

Critical

Detail

Check Point has disclosed a critical authentication bypass vulnerability, tracked as CVE-2026-16232, affecting Check Point Security Management and Multi-Domain Security Management servers. The flaw allows an unauthenticated remote attacker to obtain a valid application login token, authenticate through SmartConsole, and gain full administrator privileges over the management server. According to Check Point, successful exploitation enables attackers to modify security policies, alter security configurations, manage administrator accounts, update VPN settings, change Threat Prevention configurations, and push malicious policies to managed security gateways (firewalls). Since the Management Server controls the organization’s security infrastructure, a successful compromise could undermine the integrity of the entire network security environment.

The vulnerability is actively exploited in the wild, and Check Point confirmed that a limited number of customers have already been affected. Successful exploitation requires the Management Server to be accessible from the internet without restrictions on Trusted Clients (GUI clients), allowing attackers to remotely bypass authentication and compromise the management plane. In response, Check Point has released security hotfixes for supported versions and recommends customers apply them immediately. The vulnerability has also been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog due to confirmed active exploitation.

CVE IDSummaryCVSS Score
CVE-2026-16232Authentication bypass in Check Point Security Management and Multi-Domain Security Management allows unauthenticated attackers to obtain an application login token, gain full administrator privileges through SmartConsole, and modify firewall policies and security configurations.Critical

Affected Products

The vulnerability affects the following Check Point products:

  • Check Point Security Management R81.20
  • Check Point Security Management R82
  • Check Point Security Management R82.10
  • Multi-Domain Security Management (supported and end-of-service versions)

Note: Hotfixes are available for supported versions R81.20, R82, and R82.10.

Recommendation

Organizations using affected Check Point Management Servers are strongly advised to take the following actions to reduce the risk of compromise:

  • Apply the latest Check Point Jumbo Hotfix for the affected version as soon as possible.
  • Restrict Trusted Clients (GUI clients) to trusted IP addresses or subnets only.
  • Limit Management Server access using firewall rules and avoid exposing the management interface directly to the internet.
  • Review Check Point’s published indicators of compromise (IOCs) and investigate management server logs for signs of unauthorized access.
  • Verify the integrity of firewall policies, administrator accounts, VPN configurations, and Threat Prevention settings after applying updates.
  • Continue monitoring for suspicious management activities and ensure only authorized administrators can access the Management Server.

Source

https://www.helpnetsecurity.com/2026/07/23/check-point-vulnerability-cve-2026-16232