Check Point has released security updates to address multiple high severity vulnerabilities affecting its Security Management and Multi Domain Security Management (MDSM) products, including a critical authentication bypass flaw that is being actively exploited in real world attacks. The company confirmed that a limited number of customers have already been targeted through the vulnerability and has urged organizations using affected products to install the latest security updates and strengthen access controls. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also added the flaw to its Known Exploited Vulnerabilities catalog, requiring Federal Civilian Executive Branch agencies to apply the necessary patches by July 25, 2026.
The most severe issue, tracked as CVE 2026 16232 with a CVSS score of 9.3, affects the SmartConsole login process and allows an unauthenticated remote attacker to obtain an application login token that can be used to authenticate with full administrative privileges. According to the vulnerability description, successful exploitation enables attackers to modify security policies and security configurations within affected environments. Remote exploitation is possible when the Management Server is accessible from the internet and the configuration does not restrict Trusted Clients. Lotem Finkelstein, Vice President of Research at Check Point, said the company is aware of a small number of customers that have been targeted through this vulnerability and confirmed that those customers have already been notified. He added that the issue affects only a specific deployment scenario in which the management interface is exposed directly to the internet without IP address restrictions. Check Point also released several indicators of compromise associated with the observed activity, including the IP addresses 151.241.99.207, 151.241.99.233, 158.62.198.182, 192.142.10.99, 139.28.37.250, and 194.213.18.137 to help organizations identify potential malicious activity within their environments.
Alongside CVE 2026 16232, Check Point addressed two additional vulnerabilities affecting its management products. CVE 2026 62144, which also carries a CVSS score of 9.3, is another authentication bypass vulnerability that allows an unauthenticated remote attacker to execute administrative commands on the Management Server, including run script and exec command operations on the Security Gateway. The third issue, tracked as CVE 2026 62145 with a CVSS score of 7.5, affects the Check Point Gaia Portal and allows an authenticated user with read only portal privileges to execute commands with root level permissions because of improper privilege management. Similar to the first vulnerability, successful exploitation of CVE 2026 62144 requires management access without firewall protection or without restrictions on Trusted Clients. All three vulnerabilities impact multiple product versions, including R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, and R82.10.
Check Point has advised customers to install the July 22 Jumbo hotfix as soon as possible and implement additional security measures to reduce exposure. The company recommends limiting Trusted Clients to approved IP addresses or subnets, securing Management Server access through firewall protections, and restricting administrative access to trusted networks only. These recommendations are intended to reduce the likelihood of unauthorized access, particularly in deployments where management interfaces are accessible from external networks. The addition of CVE 2026 16232 to CISA’s Known Exploited Vulnerabilities catalog further highlights the importance of timely patch management and secure configuration practices for organizations operating Check Point Security Management and Multi Domain Security Management environments.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





