Threat Overview
Check Point has issued an urgent security advisory on August 25, 2026, describing three critical vulnerabilities that impact its Security Management, Multi‑Domain Management, Quantum Security Gateway, and Gaia operating system products. The most significant issue, CVE-2026-16232, enables an unauthenticated remote attacker to bypass the SmartConsole login process and gain full administrative control over an exposed Check Point Management Server. According to the vendor, this exploit has already been exercised against a handful of customers before patches were released.
CVE-2026-16232: SmartConsole Authentication Bypass
This flaw allows an attacker who can reach a vulnerable Management Server to obtain an application login token. The token can be used to authenticate through SmartConsole with full administrative privileges, without requiring any legitimate credentials. Successful exploitation can result in the modification of firewall policies, administrative accounts, managed objects, and gateway settings. Because the Management Server orchestrates security gateways and centrally administered firewall policies, compromise of this system could have consequences extending beyond the server itself.
Attackers with administrative access could:
- Modify firewall and network access policies
- Create or alter administrator accounts
- Insert malicious rules or weaken existing protections
- Change network objects and gateway configurations
- Enable unauthorized connectivity into protected environments
- Interfere with logging, monitoring, or incident investigation
- Establish persistent administrative access
- Use altered policies to support lateral movement or data exfiltration
Remote exploitation is possible when the attacker can connect to the Management Server IP address and the environment does not restrict SmartConsole Trusted Clients to approved IP addresses or networks. This exposure condition is important: the vulnerability does not mean every Check Point deployment is immediately exploitable from the internet. However, organizations should not assume they are safe without verifying their actual management‑plane exposure and Trusted Clients configuration.
CVE-2026-62144: Management Command Execution
This separate authentication bypass vulnerability affects Check Point Security Management and Multi‑Domain Security Management. An unauthenticated remote attacker with access to the Management Server may execute administrative commands such as run‑script and exec‑command without valid credentials. These commands can be extended from the Management Server to managed Security Gateways. While no active exploitation has been reported for CVE-2026-62144, it should be treated as critical because it can provide an unauthenticated attacker with administrative command execution across centrally managed security infrastructure.
CVE-2026-62145: Gaia Portal Privilege Escalation
In this flaw, an attacker who already possesses a valid account with read‑only Gaia Portal privileges can exploit an improper privilege management issue to execute commands with root privileges. The vulnerability requires authentication, but successful exploitation grants the attacker full operating‑system access. Root‑level access may allow an attacker to alter system configurations, access sensitive information, disable controls, install persistent tooling, or interfere with system integrity and availability. No wild exploitation has been reported for CVE-2026-62145.
Affected Products and Versions
The vulnerabilities affect a wide range of Check Point products across multiple supported and legacy release branches. Affected versions include R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, and R82.10. The specific products impacted vary by vulnerability: CVE-2026-16232 affects Security Management and Multi‑Domain Management; CVE-2026-62144 affects Security Management and Multi‑Domain Security Management; CVE-2026-62145 impacts Quantum Security Gateway, Security Management, Multi‑Domain Management, and related Gaia Portal deployments. Organizations should consult Check Point’s SecureKnowledge articles for the exact fixed Jumbo Hotfix take applicable to each installed version.
Active Exploitation
Check Point confirmed that CVE-2026-16232 was exploited against a handful of customers operating Management Servers exposed directly to the internet without IP restrictions. The vendor has not publicly disclosed the identity, motivation, or origin of the threat actor, nor has it described the complete post‑exploitation activity observed in compromised environments. CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog on July 22, 2026, and directed U.S. Federal Civilian Executive Branch agencies to remediate the vulnerability by July 25, 2026.
Indicators of Compromise
Check Point published the following source IP addresses associated with observed exploitation. Organizations should search management, firewall, VPN, authentication, endpoint, SIEM, and network telemetry for connections involving these addresses:
- 151.241.99[.]207
- 151.241.99[.]233
- 158.62.198[.]182
- 192.142.10[.]99
- 139.28.37[.]250
- 194.213.18[.]137
These IP addresses should not be treated as complete or permanent detection coverage. Attackers may change infrastructure, route traffic through proxies, or use previously compromised systems. Their absence from logs does not prove that a system was not targeted or compromised.
Mitigation and Remediation
Check Point recommends the following actions immediately:
- Install the July 22, 2026 Jumbo Hotfix. Apply the latest supported Jumbo Hotfix containing fixes for CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145. Confirm that installation completed successfully and that the running hotfix take is newer than the affected version documented by Check Point.
- Restrict Trusted Clients. Configure Trusted Clients so that SmartConsole and other management connections are accepted only from authorized administrative IP addresses or tightly controlled management subnets.
- Remove direct internet exposure. Do not expose Check Point Management Servers or Gaia Portal interfaces directly to the public internet. Place management services behind appropriate firewall rules, private management networks, or secure administrative access controls.
- Verify control‑connection protections. Confirm that implied rules for Check Point control connections are enabled and that management access is protected by firewall policy.
- Review administrative activity. Investigate recent administrator sessions, application tokens, account changes, command execution, policy modifications, and gateway configuration changes.
- Rotate potentially exposed credentials and tokens. Where compromise is suspected, revoke application tokens, reset administrative credentials, review API users, and invalidate unauthorized sessions.
These mitigation steps address the most critical aspects of the vulnerabilities and help prevent further exploitation while organizations complete the patching process.
Recommendations for Security Analysts
Security analysts should incorporate the following actions into their monitoring and incident response workflows:
- Include the sanitized IP addresses in threat‑intelligence feeds and correlation rules.
- Ensure that management‑plane traffic is logged with sufficient granularity to detect anomalous login attempts or token usage.
- Implement network segmentation to isolate management services from general network traffic.
- Apply least‑privilege principles for all administrative accounts and enforce multi‑factor authentication wherever possible.
- Maintain an inventory of all Check Point products and their current firmware/hotfix levels, and schedule regular vulnerability scanning.
By following these recommendations, organizations can reduce the risk of successful exploitation and strengthen their overall security posture against similar authentication bypass and privilege escalation threats.

