{"id":1964,"date":"2026-07-23T08:47:51","date_gmt":"2026-07-23T08:47:51","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1964"},"modified":"2026-07-23T08:47:51","modified_gmt":"2026-07-23T08:47:51","slug":"check-point-patches-exploited-smartconsole-flaw-allowing-full-admin-access","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1964","title":{"rendered":"Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 23, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Network Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiTBN3LZDMeKkPoMsoNtsGp_s0KYwVrmhhKHQsQtqgtAN1WAKeS7L-aN1hiehoBwnPi6f1gziIEecy5GlPdAVlWKPlzVprrqHLTLE3tcMZu4NK8QDoRxxS22HEFxfIpyrXnqr8O9b9akb1VVr9dmmmdwzHmhTFTVX4Cpv6WkFwSpz62tr6XKEDvKp5m0aUu\/s1700-e365\/checkpoint.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Check Point has <a href=\"https:\/\/blog.checkpoint.com\/security\/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232\/\" target=\"_blank\">released<\/a> security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come <span data-push-topic=\"active_exploitation:c, check point:t, enterprise security:i\" data-push-label=\"Active Exploitations\">under active exploitation in the wild<\/span>.<\/p>\n<p>The security flaw, tracked as <strong><a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk185169\/\" target=\"_blank\">CVE-2026-16232<\/a><\/strong> (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.<\/p>\n<p>\u00abSuccessful exploitation allows the attacker to modify security policies and security configurations,\u00bb according to a description of the flaw in CVE.org. \u00abRemote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Lotem Finkelstein, vice president of research at Check Point, said the company is aware of a small number of customers being targeted by this flaw, and that it has already notified them. It did not disclose the nature of the attacks or when they were discovered.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>\u00abThis only affects a very specific configuration &#8211; when Management is exposed directly to the internet without IP restrictions,\u00bb Finkelstein added.<\/p>\n<p>The cybersecurity vendor has shared the below indicators of compromise (IoCs) associated with the activity &#8211;<\/p>\n<ul>\n<li>151.241.99[.]207<\/li>\n<li>151.241.99[.]233<\/li>\n<li>158.62.198[.]182<\/li>\n<li>192.142.10[.]99<\/li>\n<li>139.28.37[.]250<\/li>\n<li>194.213.18[.]137<\/li>\n<\/ul>\n<p>Patches have also been released for two other flaws &#8211;<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk185152\/\" target=\"_blank\">CVE-2026-62144<\/a><\/strong> (CVSS score: 9.3) &#8211; An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management that allows an unauthenticated remote attacker to execute administrative commands on the Management Server, including run-script and exec-command on Security Gateway.<\/li>\n<li><strong><a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk185153\/\" target=\"_blank\">CVE-2026-62145<\/a><\/strong> (CVSS score: 7.5) &#8211; An improper privilege management vulnerability in Check Point Gaia Portal that allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.<\/li>\n<\/ul>\n<p>Like in the case of CVE-2026-16232, successful exploitation of CVE-2026-62144 requires management access without Firewall protection or no restrictions on Trusted Clients (GUI clients). All three issues impact the following versions &#8211;<\/p>\n<ul>\n<li>R77.30<\/li>\n<li>R80<\/li>\n<li>R80.10<\/li>\n<li>R80.20<\/li>\n<li>R80.30<\/li>\n<li>R81<\/li>\n<li>R81.10<\/li>\n<li>R81.20<\/li>\n<li>R82<\/li>\n<li>R82.10<\/li>\n<\/ul>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thn.news\/sygnia-webinar\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhleDdO_4O9-8Pkmidym8Pi9yV4V4jI_M5U0iNRDuoW5Jz3pq7DskZI9OqIChqmY1soaW1ppsC8VLeO55vxSh1m5Q8MJ9ZHuEOSNO5q7K-LwrF6IxrRfCIJOFyoBGaLXGZpkSo8tDirSz-9LmmoOs31tQTlvJWBMLiWJKqMFFaiMmNLV3l-p8zXaFm1VmGG\/s728-e100\/sygnia-d-2.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Customers are recommended to apply the July 22 Jumbo hotfix, limit Trusted Clients (GUI clients) to trusted IP addresses\/subnets, secure Management access with Firewall, and restrict access to trusted IP addresses.<\/p>\n<p>The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/07\/22\/cisa-adds-two-known-exploited-vulnerabilities-catalog\" target=\"_blank\">add<\/a> the flaw to its Known Exploited Vulnerabilities (<a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/07\/22\/cisa-adds-two-known-exploited-vulnerabilities-catalog\" target=\"_blank\">KEV<\/a>) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by July 25, 2026.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 23, 2026Vulnerability \/ Network Security Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1965,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[130,129,60,1958,128,70,753,57,1959,2680],"class_list":["post-1964","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-access","tag-admin","tag-allowing","tag-check","tag-exploited","tag-flaw","tag-full","tag-patches","tag-point","tag-smartconsole"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1964","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1964"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1964\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1965"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1964"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1964"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1964"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}