

Affected Environment
Check Point Security Management Server and Multi-Domain Security Management Server (MDS), all versions from R77.30 through R82.10.
Threat Overview
CVE-2026-16232 (CVSS 9.3): authentication bypass in SmartConsole allows unauthenticated remote attackers to obtain admin-level login tokens.
Exposure Timeline
Actively exploited in the wild as of 23rd July 2026. No confirmed patch available at time of report issuance.
Attack Surface
Internet-exposed Management Server IPs with Trusted Clients set to Any are directly reachable by unauthenticated remote attackers.
Technical Root Cause
Flaw in SmartConsole login process allows application token issuance without valid credential verification.
Exploitation Pathway
Attacker reaches Management Server IP remotely, obtains valid session token, authenticates with full administrator privileges.
Operational Impact
Successful exploitation enables modification of firewall security policies and configurations, directly undermining network defences.
Strategic Impact
Compromise of security management infrastructure can cascade across all managed gateways, affecting the entire protected network estate.
Required Mitigation
Restrict Trusted Clients to specific IP addresses or subnets immediately. Apply Check Point patches after testing. Firewall management access to trusted IPs only.
Incident Response Guidance
Search SmartConsole Audit Logs for Authentication method: application token. Cross-reference known attacker IPs: 151.241.99.207, 151.241.99.233, 158.62.198.182, 192.142.10.99, 139.28.37.250.
References
Check Point Security Advisory, Check Point Hardening Best Practices Guide, CVE-2026-16232
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




