CVE-2026-16232: Check Point SmartConsole Authentication Bypass Actively Exploited, Added to CISA KEV

CVE-2026-16232 (TL-2026-1650) is a critical-severity software vulnerability scored CVSS 9.3, first published 2026-07-23 and last reviewed 2026-08-03. It has no confirmed attribution, affects Check Point Software Technologies Security Management Server, references 3 CVEs (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145), maps to 33 MITRE ATT&CK techniques (T1005, T1016, T1018), and is covered by 9 detection rules and 39 indicators of compromise.

Key facts for TL-2026-1650

Threat ID
TL-2026-1650
Severity
CRITICAL
CVSS
9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-23
Last reviewed
2026-08-03
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, critical-infrastructure, telecoms, manufacturing
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
39
Updates
2026-08-03 · 6 updates · revalidated 5×

A critical authentication bypass (CVSS 9.3) in Check Point Security Management / Multi-Domain Management allows an unauthenticated remote attacker to obtain an administrative application login token via the SmartConsole login process, primarily where management interfaces are exposed directly to the internet without IP-based restrictions. Confirmed under active, limited-scope exploitation and added to CISA's KEV catalog on 2026-07-22; Check Point shipped a Jumbo Hotfix the same day alongside two related, not-yet-exploited CVEs.

How CVE-2026-16232 works

CVE-2026-16232 is an improper authentication vulnerability (CWE-287) in the SmartConsole login process of Check Point Security Management Server and Multi-Domain Security Management Server (MDS). The flaw allows an unauthenticated remote attacker who can reach the Management Server's network interface to obtain an application login token normally issued only after successful authentication. That token can then be used to log in to SmartConsole with full administrative privileges, giving the attacker the ability to view and modify security policy, alter Gateway configurations, push malicious rule changes, and pivot toward managed Security Gateways across the enterprise. Exploitation is gated by a specific but common misconfiguration: the Management Server (or MDS) must be reachable from the internet and the 'Trusted Clients' (GUI clients) setting must not be restricted to a defined allow-list of IP addresses/subnets (i.e., left at 'Any'). Check Point discovered the vulnerability during a routine internal 'BLAST' security-review program and confirmed, at disclosure, that a small number of customers had already been targeted in the wild. Two related but unexploited vulnerabilities were disclosed and patched in the same Jumbo Hotfix cycle: CVE-2026-62144, a Security Management authentication-bypass-plus-command-execution flaw (CVSS 9.3) letting an unauthenticated attacker run arbitrary commands on the Management server and pushed Security Gateways, and CVE-2026-62145, a Gaia Portal local privilege escalation (CVSS 7.5) letting a read-only authenticated admin run commands as root. Check Point released a Jumbo Hotfix Accumulator on 2026-07-22 (R82.10 Take 36+, R82 Take 118+, R81.20 Take 158+) closing all three issues, and CISA added CVE-2026-16232 to the Known Exploited Vulnerabilities catalog the same day under Binding Operational Directive 26-04, with a remediation due date of 2026-07-25. Six attacker-associated IP addresses were published as indicators of the observed exploitation activity, and defenders were pointed to a specific audit-log signature ('Authentication method: application token') for hunting.

MITRE ATT&CK techniques used in TL-2026-1650

Collection

T1005 Data from Local System; T1213 Data from Information Repositories; T1602 Data from Configuration Repository

Discovery

T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1087 Account Discovery; T1518 Software Discovery

Lateral Movement

T1021 Remote Services; T1210 Exploitation of Remote Services

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

Defense Evasion

T1070 Indicator Removal

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Persistence

T1098 Account Manipulation; T1136 Create Account

Credential Access

T1212 Exploitation for Credential Access; T1528 Steal Application Access Token; T1606 Forge Web Credentials

Impact

T1489 Service Stop; T1565.001 Data Manipulation: Stored Data Manipulation

lateral-movement

T1550 Use Alternate Authentication Material

defense-impairment

T1556 Modify Authentication Process; T1685 Disable or Modify Tools; T1686 Disable or Modify System Firewall

Resource Development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

Reconnaissance

T1590 Gather Victim Network Information; T1595 Active Scanning

Affected products and versions in CVE-2026-16232

  • Check Point Software Technologies — Security Management Server
    Vulnerable versions: R77.30; R80; R80.10; R80.20; R80.30; R80.40; R81; R81.10; R81.20; R82
    Fixed in: R82.10 Jumbo HFA Take 36+; R82 Jumbo HFA Take 118+; R81.20 Jumbo HFA Take 158+
  • Check Point Software Technologies — Multi-Domain Security Management Server (MDS)
    Vulnerable versions: R77.30; R80; R80.10; R80.20; R80.30; R81; R81.10; R81.20; R82; R82.10
    Fixed in: R82.10 Jumbo HFA Take 36+; R82 Jumbo HFA Take 118+; R81.20 Jumbo HFA Take 158+
  • Check Point Software Technologies — SmartConsole
    Vulnerable versions: R81.10; R81.20; R82; R82.10
    Fixed in: R82.10 Jumbo HFA Take 36+; R82 Jumbo HFA Take 118+; R81.20 Jumbo HFA Take 158+
  • Check Point Software Technologies — Gaia Portal (Security Gateway / Security Management)
    Vulnerable versions: R77.30; R80; R80.10; R80.20; R80.30; R81; R81.10; R81.20; R82; R82.10
    Fixed in: R82.10 Jumbo HFA Take 36+; R82 Jumbo HFA Take 118+; R81.20 Jumbo HFA Take 158+

Remediation for CVE-2026-16232

Patches

  • Jumbo Hotfix Accumulator for R82.10, Take 36 or later
  • Jumbo Hotfix Accumulator for R82, Take 118 or later
  • Jumbo Hotfix Accumulator for R81.20, Take 158 or later

Immediate actions

  • Install the Jumbo Hotfix Accumulator released 2026-07-22 (R82.10 Take 36+, R82 Take 118+, R81.20 Take 158+) on all Security Management / Multi-Domain Management servers
  • Restrict SmartConsole 'Trusted Clients' (GUI clients) to a specific allow-list of IP addresses/subnets instead of 'Any'
  • Firewall-protect the Management Server / MDS interface so it is not reachable directly from the internet
  • Search Management Server audit logs for events with Authentication method: application token to identify prior exploitation attempts
  • Block the six published attacker IP addresses at the network perimeter

Workarounds

  • If patching is not immediately possible, restrict Trusted Clients to a defined IP/subnet allow-list and block internet access to the Management Server as an interim compensating control

Longer-term hardening

  • Adopt Check Point's Gateway and Management Server Hardening Best Practices Guide
  • Enable implied rules for control connections and review all administrative access paths quarterly
  • Enable Multi-Factor Authentication for all Gaia OS / SmartConsole administrators
  • Restrict Gaia Portal (System Management > Host Access) to authorized hosts/subnets only
  • Maintain an internet-exposure inventory of all management-plane interfaces across the security stack

CVEs associated with CVE-2026-16232

CVE-2026-16232, CVE-2026-62144, CVE-2026-62145

Weaknesses (CWE) in CVE-2026-16232

CWE-287, CWE-269

Timeline of CVE-2026-16232

  • Check Point's internal 'BLAST' security-review program identifies CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145 during routine review, and separately flags that CVE-2026-16232 has already been exploited in the wild against a handful of customers.
  • NHS England Digital publishes cyber alert CC-4820 warning the UK health sector about CVE-2026-16232.
  • CISA adds CVE-2026-16232 to the Known Exploited Vulnerabilities catalog under Binding Operational Directive 26-04, setting a remediation due date of 2026-07-25.
  • Check Point confirms CVE-2026-16232 has been actively exploited in the wild, affecting a small number of customers with internet-exposed, unrestricted Management interfaces.
  • Check Point releases the Jumbo Hotfix Accumulator (R82.10 Take 36+, R82 Take 118+, R81.20 Take 158+) fixing all three vulnerabilities the same day as disclosure.
  • Check Point publishes advisories sk185169 (CVE-2026-16232), sk185152 (CVE-2026-62144), and sk185153 (CVE-2026-62145).
  • Rapid7 published an Emerging Threat Response (ETR) blog analyzing CVE-2026-16232, publishing the six attacker-associated IP addresses and detection guidance.
  • Broader security media (including coverage grouping the flaw with an active SharePoint exploitation alert) reports CISA's active-exploit warning for Check Point SmartConsole, urging immediate patching.
  • Cyber Security News publishes coverage of the active exploitation and KEV addition, listing six attacker-associated IP addresses observed during exploitation.
  • Vulnerability detection/scanning checks for CVE-2026-16232 became publicly available per Rapid7 reporting, enabling defenders to test exposure.
  • The Hacker News published coverage summarizing all three CVEs (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145) and Check Point's emergency patch guidance.
  • CISA BOD 26-04 remediation deadline for federal agencies to apply the Check Point patch or mitigations for CVE-2026-16232.
  • Rapid7 Labs publishes a full root-cause technical analysis of CVE-2026-16232, detailing the SIC distinguished-name trust-boundary flaw and the complete SIC-bootstrap-to-SmartConsole exploit chain.
  • Rapid7 researcher Stephen Fewer publishes a public Python PoC/validation script (sfewer-r7/CVE-2026-16232) on GitHub; The Hacker News reports on the public release.

Update history for TL-2026-1650

Sources cited for CVE-2026-16232

Threats related to CVE-2026-16232

Detection coverage for TL-2026-1650

As of 2026-08-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1650 across Splunk SPL, Microsoft KQL and Sigma, covering 39 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats