Qualysec

Check Point Patches Critical SmartConsole Zero-Day Exploited in Attacks

Fri Jul 24 2026
Check Point Patches Critical SmartConsole Zero-Day Exploited in Attacks

A vendor of cybersecurity solutions, Check Point Software Technologies, has issued emergency fixes for its SmartConsole management application for a “critical” zero-day vulnerability. The bug, dubbed CVE-2026-16232, is being weaponized by attackers who are trying to gain full access to enterprise security management systems. 

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its ‘Known Exploited Vulnerabilities’ (KEV) list and mandated its patching in federal civilian agencies in its Binding Operational Directive (BOD) 26-04.

Technical Overview: How the Flaw Works

The vulnerability, CVE-2026-16232, has a CVSS score of 9.3 (Critical) and is a result of improper authentication (CWE-287). It allows an unauthenticated remote attacker to get a valid application login token without providing any credentials.

The attacker can use this token to log into SmartConsole as an admin. From there, threat actors can re-configure firewall policies, re-configure security, and then move deeper into enterprise networks.

[Unauthenticated Attacker] 

       │

       ▼ (Displays a custom request to an exposed server)

[Management Server / MDS] 

       │

      Issues session token because of CWE-287 – Improper Validation 

[Application Token Granted] 

       │

       ▼ (Logs in via SmartConsole)

[Full Administrative Control over Firewalls & Policies]

CheckPoint researchers discovered the vulnerability in the context of their BLAST (Business Logic Attack Surface Testing) research to evaluate the readiness of AI for business use and they have observed live attacks on this vulnerability. The vendor has stated that they have already issued private notifications on these customers.

This is the newest of Check Point’s list of problems pointed out by U.S. authorities, and it is being called CVE-2026-16232. In June, CISA released a June call to action for federal agencies to address two vulnerabilities, CVE-2026-50751 (authentication bypass for Remote Access VPN and Mobile Access) and CVE-2026-50765 (Elevation of Privilege for Remote Assistance) that could allow for ransomware attacks. CISA has classified CVE-2024-24919 as an actively exploited vulnerability for Check Point’s Quantum Security Gateways in 2024.

Key Exposure Condition: Attack is successful only if the Security Management Server or Multi-Domain Management (MDS) instance is directly connected with the public Internet without any IP-based restriction.

Affected Systems and Additional Disclosures

The following tracks are considered as major releases and are affected by vulnerability:

  • Check Point Software Versions: R81.10, R81.20, R82 and R82.10 (Previous versions of the release trains may be affected too).
  • Core Affected Components: Security Management Server, Multi-Domain Security Management (MDS), and SmartConsole GUI interfaces are Core Affected Components.

In addition to CVE-2026-16232, Check Point revealed two non-exploited side vulnerabilities that it found during the internal audit:

  • CVE-2026-62144 (CVSS 9.3): Management servers authentication bypass and privilege escalation.
  • CVE-2026-62145 (CVSS 7.5): Local privilege escalation vulnerability in GaiaOS WebUI, Firewall and Multi-Domain Log Servers.

Technical Indicators and Threat Hunting

Security teams should take a peek at the SmartConsole logs in Logs & Monitor > Logs & Events > Audit Logs View to see who is accessing the network. Pay attention to logins with the following authentication type: application token and external ip address is untrusted.

CheckPoint and CISA identified the following IP addresses used to attempt to exploit and conduct reconnaissance:

Indicator of Compromise (IoC) Threat Activity Classification
151.241.99.207 Observed exploitation attempts
151.241.99.233 Observed exploitation attempts
158.62.198.182 Suspicious activity linked to attacks
192.142.10.99 Potential attacker infrastructure
139.28.37.250 Malicious traffic source
194.213.18.137 System targeting traffic

In the vulnerabilities disclosure, Check Point has released a Jumbo Hotfix for July 22 to address two additional high‑severity vulnerabilities, CVE-2026-62144 (authentication bypass and privilege escalation in management products) and CVE-2026-62145 (local privilege escalation in GaiaOS WebUI and other components). The Hotfix should be applied as soon as possible.

Check Point and CISA recommend patching is not implemented right away, and instead, hardening is recommended:

  • Only trusted IP addresses and subnets are allowed to access and control SmartConsole.
  • Use firewall rules and network filters to block Internet access to block management interfaces.
  • Make sure that implied control-connection rules are enabled on and trusted clients are limited.
  • Follow Check Point’s Gateway and Management Hardening Best Practices.
  • Regularly check Check Point’s IoC in SmartConsole and network logs.

Get an Attack Surface Security Assessment

Get a Quote

Let's work together to secure your business!

Please fill out the form to let us know about your cybersecurity needs and our professionals will reach out shortly to discuss your unique needs.

Total No. Of Vulnerabilities

0+

Total No. Of Vulnerabilities

Years in Business

0+

Years in Business

Assessment Completed

0+

Assessment Completed

Trusted Clients

0+

Trusted Clients

Countries Served

0+

Countries Served

Subscribe to Newsletter