Particle.news

Check Point Patches Exploited SmartConsole Authentication Bypass

Unauthenticated attackers can obtain admin tokens to change security policy, triggering an urgent federal remediation order.

Overview

  • The flaw CVE-2026-16232, which Check Point disclosed with a July 22 hotfix, lets an unauthenticated remote actor obtain a SmartConsole application login token and sign in with full administrative privileges.
  • An attacker who succeeds can modify security policies and configurations on Security Management and Multi‑Domain Management servers, creating the potential for network‑wide compromise of gateways and rules.
  • Check Point has published a July 22 Jumbo hotfix, published attacker indicators of compromise including six IP addresses, and advised customers to restrict Trusted Clients and block Management Server access from the internet.
  • Multiple outlets reported active exploitation against a very small number of targeted customers and CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog with a Federal Civilian Executive Branch remediation deadline of July 25, 2026.
  • Administrators should prioritize the July 22 hotfix, firewall Management interfaces to trusted IPs only, scan SmartConsole audit logs for application‑token logins and the listed IoC IPs, and note that Check Point also patched two related high‑severity management flaws.