1. Executive summary
Check Point has released security updates addressing multiple vulnerabilities in Security Management and Multi-Domain Management (MDSM) products, including CVE-2026-16232 — a critical improper authentication flaw (CVSS 9.1, CWE-287) in the SmartConsole login process that is confirmed in the CISA KEV catalog (added 2026-07-22). The vulnerability allows an unauthenticated remote attacker to obtain an application login token and authenticate with full administrative privileges, enabling modification of security policies and configurations. Active exploitation has been confirmed against a small number of customers whose Management Server IP addresses are exposed directly to the internet without IP restrictions on Trusted Clients. EMEA financial services running affected Check Point versions with internet-exposed management interfaces are at immediate risk of full security policy compromise.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 19: reporting of major ICT-related incidents to competent authorities | Active exploitation of CVE-2026-16232 confirmed in the wild against a small number of customers, enabling full administrative access to security management infrastructure — a major incident if it occurs in a financial entity. | Clients who detect exploitation or confirm exposure of management interfaces must assess whether the incident meets the classification threshold for major ICT-related incident reporting to their competent authority under DORA Art. 19, read with the classification criteria in Art. 18. |
| DORA Art. 24: digital operational resilience testing — general requirements | The vulnerability requires a specific configuration (internet-exposed Management Server without IP restrictions on Trusted Clients) that is discoverable through network exposure testing. | Clients should incorporate checks for internet-exposed Check Point management interfaces and Trusted Client configuration into their DORA Art. 24 testing programmes to identify and remediate exposure before exploitation. |
| NIS2 Art. 23: incident reporting obligations | Active exploitation of a KEV-listed vulnerability in critical network security management infrastructure, where compromise could affect the availability and integrity of essential services. | NIS2 in-scope organisations that confirm exploitation or detect compromise of Check Point management infrastructure must evaluate their incident reporting obligations under Art. 23, including the early warning and notification timelines. |
3. Technical analysis & attack chain
Vulnerability details
CVE-2026-16232 is an improper authentication vulnerability (CWE-287) in the Check Point SmartConsole login process. The verified NVD record assigns CVSS 9.1 CRITICAL; the source article from The Hacker News quotes CVSS 9.3 — this discrepancy is noted but the authoritative NVD score of 9.1 is used throughout this advisory. The flaw allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Prerequisites for exploitation
- Internet access to the Management Server IP address
- A configuration that does not restrict Trusted Clients (GUI clients)
Per Check Point VP of Research Lotem Finkelstein, the vulnerability "only affects a very specific configuration — when Management is exposed directly to the internet without IP restrictions."
Confirmed attack chain
- Reconnaissance: The attacker identifies a Check Point Management Server with an IP address reachable from the internet, where Trusted Clients (GUI clients) are not restricted to specific IP addresses or subnets.
- Authentication bypass: The unauthenticated remote attacker exploits CVE-2026-16232 to obtain a valid application login token for SmartConsole without supplying credentials.
- Privilege escalation via token: The attacker uses the obtained token to authenticate to SmartConsole with full administrative privileges.
- Security policy modification: With full admin access, the attacker can modify security policies and security configurations on the Management Server, potentially creating firewall rule changes, disabling protections, or establishing persistent access channels.
- Lateral execution (via CVE-2026-62144, if exploited in combination): The attacker may leverage the separate authentication bypass in CVE-2026-62144 to execute administrative commands on the Management Server, including
run-scriptandexec-commandon the Security Gateway.
Additional vulnerabilities patched in this cycle
CVE-2026-62144 (CVSS 9.3 per source) — An authentication bypass in Check Point Security Management and Multi-Domain Security Management allowing an unauthenticated remote attacker to execute administrative commands on the Management Server, including run-script and exec-command on the Security Gateway. Exploitation requires management access without Firewall protection or no restrictions on Trusted Clients. Note: this CVE is not listed in the verified CISA KEV data supplied; exploitation status is unconfirmed.
CVE-2026-62145 (CVSS 7.5 per source) — An improper privilege management vulnerability in Check Point Gaia Portal allowing an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges. Note: this CVE is not listed in the verified CISA KEV data supplied; exploitation status is unconfirmed.
Affected versions
All three vulnerabilities impact the following Check Point versions:
- R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, R82.10
Attribution
No named threat actor is identified in the source material. No MITRE ATT&CK actor profile is available in the verified reference data. Attribution is unconfirmed.
Confidence caveat
The exploitation scope ("small number of customers targeted") and the IoC set are single-sourced from Check Point via The Hacker News reporting. The nature and timing of the attacks have not been disclosed. Verify IoCs before enforcement.
4. Mitigation & containment
P1 — Within 24 hours
- Identify exposed management interfaces: Locate all Check Point Security Management and MDSM servers in the estate. Determine whether the Management Server IP address is reachable from the internet. Check whether Trusted Clients (GUI clients) are configured with IP restrictions. - Check Trusted Clients configuration: In SmartConsole, navigate to Security Management > Security Gateway > VPN Clients > Trusted Clients (or equivalent path per version). Verify that allowed IP ranges are restricted to known administrator subnets only.
- Block internet exposure immediately: If the Management Server is internet-exposed, enforce network-level restrictions: - Place the Management Server behind a firewall with explicit allow-list rules for management traffic only from trusted internal IP ranges. - Remove any public IP bindings or NAT rules exposing TCP ports used by SmartConsole (typically TCP 19009 for SmartConsole GUI client access — verify per deployment).
- Apply the July 22 Jumbo hotfix: Install the Check Point July 22 Jumbo hotfix on all affected Security Management and MDSM servers. This addresses CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145.
- Hunt for exploitation: Review SmartConsole authentication logs and Management Server audit logs for unexplained login token issuance, unrecognised source IP addresses, and unauthorised security policy changes. Cross-reference against the IoCs in §5.
P2 — Within 72 hours
- Restrict Trusted Clients: Configure Trusted Clients (GUI clients) to permit only explicitly trusted IP addresses or subnets. Remove "Any" or broad CIDR ranges from the allowed list.
- Secure Management access with Firewall: Ensure all Management Server access is protected by a dedicated firewall policy. No Management Server should be directly internet-reachable.
- Patch all remaining affected versions: Ensure the July 22 Jumbo hotfix is applied across the full estate, including any MDSM domains running older versions (R77.30 through R81.10 are particularly likely to be overdue).
- Review Gaia Portal access: For CVE-2026-62145, audit all accounts with read-only Gaia Portal privileges and remove any that are no longer required. Apply the hotfix to eliminate the privilege escalation path.
P3 — Within 7 days
- Validate patch deployment: Confirm all Management Servers and MDSM instances report the hotfix as installed. Run
cpinfo -y all(or equivalent) to verify hotfix take version across the estate. - Review historical policy changes: Conduct a retrospective review of all security policy changes made in the past 90 days to identify any unauthorised modifications that may indicate prior exploitation.
- Update security architecture documentation: Ensure network diagrams reflect that Management Servers must not be internet-exposed. Incorporate this requirement into change management approval gates.
5. Indicators of compromise
The following IP addresses are associated with the exploitation activity, as shared by Check Point. These are single-sourced from Check Point via The Hacker News; verify before enforcement.
| Type | Value | Confidence | Source |
|---|---|---|---|
| ipv4 | 151.241.99[.]207 | Medium — single-sourced | Check Point via The Hacker News |
| ipv4 | 151.241.99[.]233 | Medium — single-sourced | Check Point via The Hacker News |
| ipv4 | 158.62.198[.]182 | Medium — single-sourced | Check Point via The Hacker News |
| ipv4 | 192.142.10[.]99 | Medium — single-sourced | Check Point via The Hacker News |
| ipv4 | 139.28.37[.]250 | Medium — single-sourced | Check Point via The Hacker News |
| ipv4 | 194.213.18[.]137 | Medium — single-sourced | Check Point via The Hacker News |
ipv4 151.241.99[.]207
ipv4 151.241.99[.]233
ipv4 158.62.198[.]182
ipv4 192.142.10[.]99
ipv4 139.28.37[.]250
ipv4 194.213.18[.]137
6. Detection
No file-based artefacts, command-line strings, registry keys, or mutex names are present in the source material. The IoCs are limited to IP addresses, which are best deployed as network blocklist or SIEM correlation rules rather than YARA or Sigma rules.
Recommended SIEM correlation rule: Alert on any inbound connection to a Check Point Management Server IP address originating from any of the six IoC IP addresses listed in §5. Additionally, alert on SmartConsole authentication events (login token issuance) from source IPs outside the organisation's trusted administrator IP ranges.
Insufficient indicators to author YARA or Sigma detection rules.
CVE assessment
1 referenced CVE — 1 actively exploited (CISA KEV), 1 critical (CVSS ≥ 9.0)
| CVE | CVSS | Exploited | EPSS | Summary |
|---|---|---|---|---|
| CVE-2026-16232 | 9.1 Critical | ⚠ KEV 2026-07-22 | — | An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker… |
7. Sources
- The Hacker News — "Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access" — https://thehackernews.com/2026/07/check-point-patches-exploited.html — 2026-07-23
- NVD / CISA KEV — CVE-2026-16232 — Check Point SmartConsole Improper Authentication Vulnerability — https://nvd.nist.gov/vuln/detail/CVE-2026-16232 — KEV added 2026-07-22
- BleepingComputer — "Check Point warns of SmartConsole zero-day exploited in attacks" — https://www.bleepingcomputer.com/news/security/check-point-patches-smartconsole-zero-day-exploited-in-attacks/ — 2026-07
- SecurityWeek — "New Check Point Zero-Day Vulnerability Exploited in the Wild" — https://www.securityweek.com/new-check-point-zero-day-vulnerability-exploited-in-the-wild/ — 2026-07
8. Adverse Trace position
CVE-2026-16232 is a critical vulnerability (CVSS 9.1, CWE-287) with confirmed active exploitation and CISA KEV listing (added 2026-07-22, remediation due 2026-07-25 for FCEB agencies). The attack vector is narrowly constrained to environments where the Check Point Management Server is directly internet-exposed without Trusted Client IP restrictions — a configuration that should not exist in any well-architected EMEA financial services environment but which legacy deployments or misconfigured MDSM instances may still present. The combination of CVE-2026-16232 (full admin token) and CVE-2026-62144 (administrative command execution including run-script and exec-command on Security Gateway) represents a full compromise chain for affected deployments. Clients should treat this as a P1 priority: identify and isolate any internet-exposed management interfaces within 24 hours, apply the July 22 Jumbo hotfix, and conduct retrospective log review for the six listed IoCs. Adverse Trace will monitor for additional IoCs, threat actor attribution, and any expansion of the exploitation scope. The IoC set and customer-targeting details are single-sourced from Check Point; we will update this advisory as corroboration emerges.
Published via PulseTrace — Adverse Trace threat intelligence.