Check Point SmartConsole CVE-2026-16232 Exploited: Patch Now

Brendan Smith
Brendan Smith - Cybersecurity Analyst
5 Min Read
Open SmartConsole management gateway exposed to hostile connections through an application token
An internet-exposed Check Point management plane can be reached through the SmartConsole token bypass until it is patched and restricted.

Check Point says attackers are exploiting CVE-2026-16232, a SmartConsole authentication bypass that can give a remote unauthenticated attacker full administrator access to a Security Management or Multi-Domain Management server. The company observed attacks at a handful of customers whose management systems were exposed directly to the internet without IP restrictions. Administrators should install the Jumbo Hotfix released on July 22 and restrict management access immediately.

CISA added the flaw to its Known Exploited Vulnerabilities catalog on July 22 and set a July 25 remediation deadline for US federal agencies. The issue carries a CVSS score of 9.3 and affects supported R81.10, R81.20, R82, and R82.10 releases as well as older versions.

Which Check Point systems are at risk?

Question Verified answer
Affected component Security Management and Multi-Domain Management servers used with SmartConsole.
Affected releases R81.10, R81.20, R82, R82.10, and older versions.
Highest-risk configuration The management server is reachable directly from the public internet and Trusted Clients are not limited to approved IP addresses or subnets.
Attack result An unauthenticated remote attacker can obtain an application login token and authenticate with full administrative privileges.
Required fix Install the latest Jumbo Hotfix released July 22 and restrict management-plane access.

This is a management-plane vulnerability, not a claim that every Check Point gateway or every SmartConsole workstation is compromised. Check Point’s confirmed attacks involved a specific unsafe exposure: management access open to the internet without IP restrictions. A server behind a firewall and limited to trusted administration networks has a materially smaller attack surface, but supported installations should still receive the hotfix.

Why the SmartConsole bypass matters

SmartConsole is the administrative interface used to manage security policy. According to Check Point and CISA, the flaw allows an attacker to obtain an application login token without authentication and then enter the management system with full administrator rights. That level of access can expose configuration and enable unauthorized policy or administrator changes.

The July 22 KEV listing confirms exploitation in the wild. It does not prove that every internet-exposed server has been attacked, and patching now cannot establish that no access occurred earlier. Teams responsible for other exposed security-management products may also want to review the recently exploited PAN-OS CVE-2026-0257 and the response pattern for a new CISA KEV entry.

Emergency response for CVE-2026-16232

  1. Remove direct internet exposure. Use a firewall or access-control device to allow management connections only from approved administration networks.
  2. Restrict Trusted Clients. In SmartConsole, limit GUI clients to specific trusted IP addresses or subnets. Review implied rules that permit control connections as well.
  3. Install the July 22 Jumbo Hotfix. Use the latest package for the exact management release and verify installation on every Security Management and Multi-Domain Management server.
  4. Review for prior access. Examine administrator logins, newly created or changed accounts, policy modifications, management API activity, and unexpected configuration changes. Preserve relevant logs before cleanup.
  5. Escalate suspicious evidence. If an indicator or unexplained administrator action appears, isolate the management server from untrusted networks and contact Check Point Support or the incident-response team.

IP indicators published by Check Point

Check Point associated the following source addresses with the observed activity. Search management, firewall, VPN, and upstream network logs for connections from them:

151.241.99.207
151.241.99.233
158.62.198.182
192.142.10.99
139.28.37.250
194.213.18.137

An IP match is a reason to investigate, not proof by itself: addresses can be reassigned or spoofed in unrelated records. Conversely, finding none of these six addresses does not prove the environment is clean. Attackers can change infrastructure, and the published list may not cover every attempt.

References

  1. Check Point Research. “Security Advisory: Action Required — Active Exploitation of Check Point SmartConsole Authentication Bypass (CVE-2026-16232).” Check Point, July 22, 2026, accessed July 22, 2026. Check Point security advisory.
  2. Cybersecurity and Infrastructure Security Agency. “Known Exploited Vulnerabilities Catalog.” CISA, updated July 22, 2026, accessed July 22, 2026. CISA KEV catalog.
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT ransomware—take last year, for instance, when his breakdowns caught more than 200 sneaky variants right in live scans, knocking user cleanup jobs down by a solid 40% and saving folks hours of headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?