Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
highDetails
A critical, unauthenticated authentication bypass vulnerability in Check Point Security Management allows attackers to gain full administrative privileges. The flaw resides in the SmartConsole GUI admin panel. Attackers can obtain an application login token to log in with full admin rights, enabling them to alter security policies and configurations on managed firewalls.
Affected Systems
Check Point Security Management and Multi-Domain Security Management servers.
Potential Impact
Complete takeover of network security infrastructure, including firewalls. Attackers can modify security rules to allow malicious traffic, exfiltrate data, and establish persistent access to the corporate network.
Mitigations
Apply the patch provided by Check Point immediately. This vulnerability is on the CISA KEV list with a required remediation date of 2026-07-25. Prioritize patching on all internet-facing management servers.