Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Researchers Warn of AI-Enhanced Phone Fraud Ecosystem

July 29, 2026

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

July 29, 2026

Coca Cola Reveals Subsidiary Fairlife Suffered Data Breach

July 29, 2026
Facebook X (Twitter) Instagram
Wednesday, July 29
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
News

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

Team-CWDBy Team-CWDJuly 29, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild.

The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

“Successful exploitation allows the attacker to modify security policies and security configurations,” according to a description of the flaw in CVE.org. “Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients.”

Lotem Finkelstein, vice president of research at Check Point, said the company is aware of a handful of customers being targeted by this flaw, and that it has already notified them. It did not disclose the nature of the attacks or when they were discovered.

“This only affects a very specific configuration – when Management is exposed directly to the internet without IP restrictions,” Finkelstein added.

The cybersecurity vendor has shared the below indicators of compromise (IoCs) associated with the activity –

  • 151.241.99[.]207
  • 151.241.99[.]233
  • 158.62.198[.]182
  • 192.142.10[.]99
  • 139.28.37[.]250
  • 194.213.18[.]137

Patches have also been released for two other flaws –

  • CVE-2026-62144 (CVSS score: 9.3) – An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management that allows an unauthenticated remote attacker to execute administrative commands on the Management Server, including run-script and exec-command on Security Gateway.
  • CVE-2026-62145 (CVSS score: 7.5) – An improper privilege management vulnerability in Check Point Gaia Portal that allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

Like in the case of CVE-2026-16232, successful exploitation of CVE-2026-62144 requires management access without Firewall protection or no restrictions on Trusted Clients (GUI clients). All three issues impact the following versions –

  • R77.30
  • R80
  • R80.10
  • R80.20
  • R80.30
  • R81
  • R81.10
  • R81.20
  • R82
  • R82.10

Customers are recommended to apply the July 22 Jumbo hotfix, limit Trusted Clients (GUI clients) to trusted IP addresses/subnets, secure Management access with Firewall, and restrict access to trusted IP addresses.

The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by July 25, 2026.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCoca Cola Reveals Subsidiary Fairlife Suffered Data Breach
Next Article Researchers Warn of AI-Enhanced Phone Fraud Ecosystem
Team-CWD
  • Website

Related Posts

News

Researchers Warn of AI-Enhanced Phone Fraud Ecosystem

July 29, 2026
News

Coca Cola Reveals Subsidiary Fairlife Suffered Data Breach

July 29, 2026
News

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

July 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Mobile app permissions (still) matter more than you may think

February 27, 2026

It’s all fun and games until someone gets hacked

September 26, 2025

Watch out for SVG files booby-trapped with malware

September 22, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.