- July 22, 2026
Critical Check Point Security Management Vulnerabilities Under Active Exploitation (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145)
Check Point patched three vulnerabilities in its Security Management platform on July 22nd, 2026, (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145). CVE-2026-16232 was already exploited in the wild as to seize full administrative control of firewall management servers.
Executive Summary
On July 22nd, 2026, Check Point disclosed several authentication vulnerabilities in their SmartConsole, Gaia Portal, Security Management, and Multi-Domain Security Management services. The most critical of these is under active exploitation and tracked as CVE-2026-16232.
The flaw allows an unauthenticated remote attacker the ability to obtain a login token and authenticate to the management server with full administrative privileges, enabling modification of security policies and configurations.
Check Point’s Security Management is the centralized console that pushes security policies, VPN configurations, threat prevention settings, and administrator permissions to an organization’s Check Point firewalls. Compromising it therefore presents a significant risk to internet-facing Security Management instances.
Affected Systems or Products
Product | Affected Version | Fixed Version |
|---|---|---|
Security Management Server | R81.10, R81.20, R82, R82.10 (older versions impacted as well) | Jumbo Hotfix Take 36, 118, 158, and later |
Security Management Server Multi-Domain Management | R81.10, R81.20, R82, R82.10 (older versions impacted as well) | Jumbo Hotfix Take 36, 118, 158, and later |
Gaia Portal on Security Gateway | R81.10, R81.20, R82, R82.10 (older versions impacted as well) | Jumbo Hotfix Take 36, 118, 158, and later |
Mitigations / Workarounds
Check Point released a single hotfix that remediates all three vulnerabilities; no separate action is required per CVE. Where immediate patching is not possible, apply these interim steps:
- 1.
Restrict SmartConsole Trusted Clients (GUI clients) to specific, trusted IP addresses or subnets rather than Any. This closes the preconditions for CVE-2026-16232 and CVE-2026-62144.
- 2.
Place the Management Server behind a firewall that permits only trusted administrative access and verify that implied rules for control connections are enabled.
Patches
Check Point released a hotfix on July 22nd, 2026 that addresses all three vulnerabilities. Hotfixes are confirmed as available for currently supported versions R81.20, R82, and R82.10. Further details are available in Check Point’s advisory and the corresponding GitHub security advisories linked in Sources.
Indicators of Compromise
On July 22nd, 2026, CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. Check Point has published six attacker IP addresses observed in the activity:
151.241.99[.]207151.241.99[.]233158.62.198[.]182192.142.10[.]99139.28.37[.]250194.213.18[.]137
Administrators can check for access in SmartConsole under Logs & Monitor > Logs & Events > Audit Logs View and search for events showing Authentication method: application token alongside connections to or from the listed IP addresses. CVE-2026-62144 and CVE-2026-62145 have not been reported as exploited as of publication.
Technical Details
CVE-2026-16232 is an authentication logic flaw that allows an authenticated attacker to obtain a valid login token, which allows access into the SmartConsole as an administrator. This allows an attacker to make modifications to the security policy and configuration within SmartConsole, effectively changing the security promises of existing deployments. Check Point has identified this as the only publicly exploited vulnerability in this release.
CVE-2026-62144 is another authentication issue but instead allows an attacker to bypass authentication entirely and perform various administrative commands directory on the management server. Check Point has specially identified the run-script and exec-command commands as vulnerable to abuse. These commands provide similar controls to the attacker and equally put the deployment at risk.
CVE-2026-62145 is a privilege escalation issue that allows an authenticated user to gain root access and subsequently perform commands which change the security controls on Security Management deployments.
How Beazley Security is responding
Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.
We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.
If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team.