CVE-2026-16232: Check Point SmartConsole Authentication Bypass Actively Exploited, Added to CISA KEV
CVE-2026-16232 (TL-2026-1650) is a critical-severity software vulnerability scored CVSS 9.3, first published 2026-07-23 and last reviewed 2026-08-03. It has no confirmed attribution, affects Check Point Software Technologies Security Management Server, references 3 CVEs (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145), maps to 33 MITRE ATT&CK techniques (T1005, T1016, T1018), and is covered by 9 detection rules and 39 indicators of compromise.
Key facts for TL-2026-1650
- Threat ID
- TL-2026-1650
- Severity
- CRITICAL
- CVSS
- 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-07-23
- Last reviewed
- 2026-08-03
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, critical-infrastructure, telecoms, manufacturing
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 39
- Updates
- 2026-08-03 · 6 updates · revalidated 5×
A critical authentication bypass (CVSS 9.3) in Check Point Security Management / Multi-Domain Management allows an unauthenticated remote attacker to obtain an administrative application login token via the SmartConsole login process, primarily where management interfaces are exposed directly to the internet without IP-based restrictions. Confirmed under active, limited-scope exploitation and added to CISA's KEV catalog on 2026-07-22; Check Point shipped a Jumbo Hotfix the same day alongside two related, not-yet-exploited CVEs.
How CVE-2026-16232 works
CVE-2026-16232 is an improper authentication vulnerability (CWE-287) in the SmartConsole login process of Check Point Security Management Server and Multi-Domain Security Management Server (MDS). The flaw allows an unauthenticated remote attacker who can reach the Management Server's network interface to obtain an application login token normally issued only after successful authentication. That token can then be used to log in to SmartConsole with full administrative privileges, giving the attacker the ability to view and modify security policy, alter Gateway configurations, push malicious rule changes, and pivot toward managed Security Gateways across the enterprise. Exploitation is gated by a specific but common misconfiguration: the Management Server (or MDS) must be reachable from the internet and the 'Trusted Clients' (GUI clients) setting must not be restricted to a defined allow-list of IP addresses/subnets (i.e., left at 'Any'). Check Point discovered the vulnerability during a routine internal 'BLAST' security-review program and confirmed, at disclosure, that a small number of customers had already been targeted in the wild. Two related but unexploited vulnerabilities were disclosed and patched in the same Jumbo Hotfix cycle: CVE-2026-62144, a Security Management authentication-bypass-plus-command-execution flaw (CVSS 9.3) letting an unauthenticated attacker run arbitrary commands on the Management server and pushed Security Gateways, and CVE-2026-62145, a Gaia Portal local privilege escalation (CVSS 7.5) letting a read-only authenticated admin run commands as root. Check Point released a Jumbo Hotfix Accumulator on 2026-07-22 (R82.10 Take 36+, R82 Take 118+, R81.20 Take 158+) closing all three issues, and CISA added CVE-2026-16232 to the Known Exploited Vulnerabilities catalog the same day under Binding Operational Directive 26-04, with a remediation due date of 2026-07-25. Six attacker-associated IP addresses were published as indicators of the observed exploitation activity, and defenders were pointed to a specific audit-log signature ('Authentication method: application token') for hunting.
MITRE ATT&CK techniques used in TL-2026-1650
Collection
T1005 Data from Local System; T1213 Data from Information Repositories; T1602 Data from Configuration Repository
Discovery
T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1518 Software Discovery
Lateral Movement
T1021 Remote Services; T1210 Exploitation of Remote Services
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
Defense Evasion
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Persistence
T1098 Account Manipulation; T1136 Create Account
Credential Access
T1212 Exploitation for Credential Access; T1528 Steal Application Access Token; T1606 Forge Web Credentials
Impact
T1489 Service Stop; T1565.001 Data Manipulation: Stored Data Manipulation
lateral-movement
T1550 Use Alternate Authentication Material
defense-impairment
T1556 Modify Authentication Process; T1685 Disable or Modify Tools; T1686 Disable or Modify System Firewall
Resource Development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
Reconnaissance
T1590 Gather Victim Network Information; T1595 Active Scanning
Affected products and versions in CVE-2026-16232
- Check Point Software Technologies — Security Management Server
Vulnerable versions: R77.30; R80; R80.10; R80.20; R80.30; R80.40; R81; R81.10; R81.20; R82
Fixed in: R82.10 Jumbo HFA Take 36+; R82 Jumbo HFA Take 118+; R81.20 Jumbo HFA Take 158+ - Check Point Software Technologies — Multi-Domain Security Management Server (MDS)
Vulnerable versions: R77.30; R80; R80.10; R80.20; R80.30; R81; R81.10; R81.20; R82; R82.10
Fixed in: R82.10 Jumbo HFA Take 36+; R82 Jumbo HFA Take 118+; R81.20 Jumbo HFA Take 158+ - Check Point Software Technologies — SmartConsole
Vulnerable versions: R81.10; R81.20; R82; R82.10
Fixed in: R82.10 Jumbo HFA Take 36+; R82 Jumbo HFA Take 118+; R81.20 Jumbo HFA Take 158+ - Check Point Software Technologies — Gaia Portal (Security Gateway / Security Management)
Vulnerable versions: R77.30; R80; R80.10; R80.20; R80.30; R81; R81.10; R81.20; R82; R82.10
Fixed in: R82.10 Jumbo HFA Take 36+; R82 Jumbo HFA Take 118+; R81.20 Jumbo HFA Take 158+
Remediation for CVE-2026-16232
Patches
- Jumbo Hotfix Accumulator for R82.10, Take 36 or later
- Jumbo Hotfix Accumulator for R82, Take 118 or later
- Jumbo Hotfix Accumulator for R81.20, Take 158 or later
Immediate actions
- Install the Jumbo Hotfix Accumulator released 2026-07-22 (R82.10 Take 36+, R82 Take 118+, R81.20 Take 158+) on all Security Management / Multi-Domain Management servers
- Restrict SmartConsole 'Trusted Clients' (GUI clients) to a specific allow-list of IP addresses/subnets instead of 'Any'
- Firewall-protect the Management Server / MDS interface so it is not reachable directly from the internet
- Search Management Server audit logs for events with Authentication method: application token to identify prior exploitation attempts
- Block the six published attacker IP addresses at the network perimeter
Workarounds
- If patching is not immediately possible, restrict Trusted Clients to a defined IP/subnet allow-list and block internet access to the Management Server as an interim compensating control
Longer-term hardening
- Adopt Check Point's Gateway and Management Server Hardening Best Practices Guide
- Enable implied rules for control connections and review all administrative access paths quarterly
- Enable Multi-Factor Authentication for all Gaia OS / SmartConsole administrators
- Restrict Gaia Portal (System Management > Host Access) to authorized hosts/subnets only
- Maintain an internet-exposure inventory of all management-plane interfaces across the security stack
CVEs associated with CVE-2026-16232
Weaknesses (CWE) in CVE-2026-16232
CWE-287, CWE-269
Timeline of CVE-2026-16232
- Check Point's internal 'BLAST' security-review program identifies CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145 during routine review, and separately flags that CVE-2026-16232 has already been exploited in the wild against a handful of customers.
- NHS England Digital publishes cyber alert CC-4820 warning the UK health sector about CVE-2026-16232.
- CISA adds CVE-2026-16232 to the Known Exploited Vulnerabilities catalog under Binding Operational Directive 26-04, setting a remediation due date of 2026-07-25.
- Check Point confirms CVE-2026-16232 has been actively exploited in the wild, affecting a small number of customers with internet-exposed, unrestricted Management interfaces.
- Check Point releases the Jumbo Hotfix Accumulator (R82.10 Take 36+, R82 Take 118+, R81.20 Take 158+) fixing all three vulnerabilities the same day as disclosure.
- Check Point publishes advisories sk185169 (CVE-2026-16232), sk185152 (CVE-2026-62144), and sk185153 (CVE-2026-62145).
- Rapid7 published an Emerging Threat Response (ETR) blog analyzing CVE-2026-16232, publishing the six attacker-associated IP addresses and detection guidance.
- Broader security media (including coverage grouping the flaw with an active SharePoint exploitation alert) reports CISA's active-exploit warning for Check Point SmartConsole, urging immediate patching.
- Cyber Security News publishes coverage of the active exploitation and KEV addition, listing six attacker-associated IP addresses observed during exploitation.
- Vulnerability detection/scanning checks for CVE-2026-16232 became publicly available per Rapid7 reporting, enabling defenders to test exposure.
- The Hacker News published coverage summarizing all three CVEs (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145) and Check Point's emergency patch guidance.
- CISA BOD 26-04 remediation deadline for federal agencies to apply the Check Point patch or mitigations for CVE-2026-16232.
- Rapid7 Labs publishes a full root-cause technical analysis of CVE-2026-16232, detailing the SIC distinguished-name trust-boundary flaw and the complete SIC-bootstrap-to-SmartConsole exploit chain.
- Rapid7 researcher Stephen Fewer publishes a public Python PoC/validation script (sfewer-r7/CVE-2026-16232) on GitHub; The Hacker News reports on the public release.
Update history for TL-2026-1650
- 2026-08-03 — tweetfeed.live community intel: New TL_OSINT_Scan community intel: 6 newly-corroborated indicator(s).
- 2026-07-30 — Check Point SmartConsole Authentication Bypass (CVE-2026-16232) — Rapid7 Releases PoC for Actively Exploited Zero-Day: What changed No severity/exploitability/status change (already CRITICAL/ACTIVE/ACTIVE) — the escalation is in public exploitability posture: Rapid7 published a full root-cause technical analysis (2026-07-28) and a public, working Python PoC
- 2026-07-26 — CISA Adds Two Known Exploited Vulnerabilities to Catalog: Check Point SmartConsole (CVE-2026-16232) and Microsoft SharePoint (CVE-2026-50522): What changed No change to severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), or attribution (Unattributed/Unknown, LOW confidence) — the newer report confirms rather than escalates these. The report's own CVSS reference for CVE-
- 2026-07-25 — Check Point SmartConsole Authentication Bypass (CVE-2026-16232) Exploited in the Wild, Grants Full Admin Access: What changed No field escalation — severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), and CVSS (9.3) are unchanged from the existing record. The newer report's own NVD citation (v3.1 base 9.1) is lower than the existing 9.3, so
- 2026-07-25 — Critical Check Point SmartConsole Authentication Bypass (CVE-2026-16232) Exploited in the Wild; Companion Flaws CVE-2026-62144 and CVE-2026-62145 Patched: What changed Core severity/exploitability/status unchanged (CRITICAL / ACTIVE / ACTIVE). The newer report's CVSS score of 9.1 is lower than the existing record's 9.3 despite an identical vector string; per policy this is not applied since i
- 2026-07-23 — CVE-2026-16232: Check Point SmartConsole Authentication Bypass Zero-Day Exploited in Attacks: What changed No escalation in severity/exploitability/status: still CRITICAL / ACTIVE / ACTIVE. Newer report's 9.1 CVSS is lower than the existing 9.3 and is not applied (never downgrade). New indicators (2) 2 new behavioral IOCs: abused ma
Sources cited for CVE-2026-16232
- Cyber Security News - Check Point Vulnerability Exploited
- Check Point sk185169 - CVE-2026-16232 Authentication bypass with SmartConsole login process using application token
- CISA Known Exploited Vulnerabilities Catalog - CVE-2026-16232
- NVD - CVE-2026-16232
- Check Point Blog - Security Advisory: Action Required, Active Exploitation of SmartConsole Authentication Bypass (CVE-2026-16232)
- Check Point sk185152 - CVE-2026-62144 Management Authentication Bypass and Privilege Escalation
- Check Point sk185153 - CVE-2026-62145 Local Privilege Escalation in Gaia Portal
Threats related to CVE-2026-16232
- Cisco Catalyst Center Unauthenticated Path Traversal / Arbitrary File Read Vulnerability (CVE-2026-20191)
- Check Point Security Management Authentication Bypass (CVE-2026-18574) — Unauthenticated Remote Command Execution on Security Management Server
- CVE-2026-46817: Active Exploitation Against ~950 Internet-Exposed Oracle E-Business Suite Payments Instances
- GitHub Enterprise Server 3.20.3 — Pre-Auth SSRF in Upload Endpoint (CVE-2026-9312) + Bundled "Dirty Frag" Kernel LPEs (CVE-2026-43284, CVE-2026-43500) + Mandatory GPG Signing Key Rotation
- CISA Adds Two Known Exploited Vulnerabilities to Catalog: Fortinet FortiOS Information Disclosure (CVE-2025-68686) and Arista VeloCloud Orchestrator OS Command Injection (CVE-2026-16812)
- CVE-2026-46817: Unauthenticated Arbitrary File Read in Oracle E-Business Suite Payments File Transmission Exploited Before Public PoC
Detection coverage for TL-2026-1650
As of 2026-08-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1650 across Splunk SPL, Microsoft KQL and Sigma, covering 39 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.