Check Point rushes fix for actively exploited SmartConsole bypass

Check Point patched a critical SmartConsole authentication bypass under active exploitation that gives attackers full admin access to security management servers.

CSBadmin
1 Min Read

Check Point released emergency patches for CVE-2026-16232, a critical authentication bypass in SmartConsole rated 9.3 on the CVSS scale that attackers are actively exploiting in the wild. The flaw lets unauthenticated remote attackers obtain a SmartConsole login token and gain full administrative control over Security Management and Multi-Domain Security Management servers.

Successful exploitation requires the Management Server to be internet-reachable with Trusted Client (GUI client) restrictions disabled. Check Point confirmed a limited number of customers have already been targeted and notified affected organizations. The company shared six attacker IP addresses as indicators of compromise, including addresses from Russian and Latin American ranges.

Two additional vulnerabilities were addressed in the July 22 Jumbo hotfix: CVE-2026-62144 (CVSS 9.3), another authentication bypass enabling remote administrative actions including running scripts on Security Gateways, and CVE-2026-62145 (CVSS 7.5), a privilege escalation in the Gaia Portal allowing read-only users to execute commands as root.

Administrators should immediately install the Jumbo hotfix, restrict SmartConsole Trusted Clients to approved IP addresses rather than “Any,” and protect Management Server access with firewall rules. Reviewing logs for connections from the published attacker IPs is also advised for detecting potential compromise.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.