Check Point says attackers are exploiting CVE-2026-16232, a SmartConsole authentication bypass that can give a remote unauthenticated attacker full administrator access to a Security Management or Multi-Domain Management server. The company observed attacks at a handful of customers whose management systems were exposed directly to the internet without IP restrictions. Administrators should install the Jumbo Hotfix released on July 22 and restrict management access immediately.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on July 22 and set a July 25 remediation deadline for US federal agencies. The issue carries a CVSS score of 9.3 and affects supported R81.10, R81.20, R82, and R82.10 releases as well as older versions.
Which Check Point systems are at risk?
| Question | Verified answer |
|---|---|
| Affected component | Security Management and Multi-Domain Management servers used with SmartConsole. |
| Affected releases | R81.10, R81.20, R82, R82.10, and older versions. |
| Highest-risk configuration | The management server is reachable directly from the public internet and Trusted Clients are not limited to approved IP addresses or subnets. |
| Attack result | An unauthenticated remote attacker can obtain an application login token and authenticate with full administrative privileges. |
| Required fix | Install the latest Jumbo Hotfix released July 22 and restrict management-plane access. |
This is a management-plane vulnerability, not a claim that every Check Point gateway or every SmartConsole workstation is compromised. Check Point’s confirmed attacks involved a specific unsafe exposure: management access open to the internet without IP restrictions. A server behind a firewall and limited to trusted administration networks has a materially smaller attack surface, but supported installations should still receive the hotfix.
Why the SmartConsole bypass matters
SmartConsole is the administrative interface used to manage security policy. According to Check Point and CISA, the flaw allows an attacker to obtain an application login token without authentication and then enter the management system with full administrator rights. That level of access can expose configuration and enable unauthorized policy or administrator changes.
The July 22 KEV listing confirms exploitation in the wild. It does not prove that every internet-exposed server has been attacked, and patching now cannot establish that no access occurred earlier. Teams responsible for other exposed security-management products may also want to review the recently exploited PAN-OS CVE-2026-0257 and the response pattern for a new CISA KEV entry.
Emergency response for CVE-2026-16232
- Remove direct internet exposure. Use a firewall or access-control device to allow management connections only from approved administration networks.
- Restrict Trusted Clients. In SmartConsole, limit GUI clients to specific trusted IP addresses or subnets. Review implied rules that permit control connections as well.
- Install the July 22 Jumbo Hotfix. Use the latest package for the exact management release and verify installation on every Security Management and Multi-Domain Management server.
- Review for prior access. Examine administrator logins, newly created or changed accounts, policy modifications, management API activity, and unexpected configuration changes. Preserve relevant logs before cleanup.
- Escalate suspicious evidence. If an indicator or unexplained administrator action appears, isolate the management server from untrusted networks and contact Check Point Support or the incident-response team.
IP indicators published by Check Point
Check Point associated the following source addresses with the observed activity. Search management, firewall, VPN, and upstream network logs for connections from them:
151.241.99.207
151.241.99.233
158.62.198.182
192.142.10.99
139.28.37.250
194.213.18.137
An IP match is a reason to investigate, not proof by itself: addresses can be reassigned or spoofed in unrelated records. Conversely, finding none of these six addresses does not prove the environment is clean. Attackers can change infrastructure, and the published list may not cover every attempt.
References
- Check Point Research. “Security Advisory: Action Required — Active Exploitation of Check Point SmartConsole Authentication Bypass (CVE-2026-16232).” Check Point, July 22, 2026, accessed July 22, 2026. Check Point security advisory.
- Cybersecurity and Infrastructure Security Agency. “Known Exploited Vulnerabilities Catalog.” CISA, updated July 22, 2026, accessed July 22, 2026. CISA KEV catalog.

