Check Point SmartConsole Flaw Exploited in the Wild
Check Point, which makes firewall and network security software used by enterprises worldwide, has patched a critical authentication bypass flaw that attackers were already exploiting, according to The Hacker News.
The vulnerability, CVE-2026-16232 (CVSS 9.3, Critical), lives inside the login process of SmartConsole, the management interface administrators use to control Check Point security systems. An attacker needed no username or password. Instead, they could reach across the internet, grab a valid login token, and walk straight in with full administrative rights.
Once inside, they could rewrite security policies, change firewall rules, and reconfigure defences entirely. Think of it as someone not just picking your lock, but then being handed the keys to every room in the building.
The catch: exploitation only works when the Management Server is exposed directly to the internet without IP restrictions in place. Check Point says a small number of customers were targeted and have been notified.
Patches are now available via the July 22 Jumbo hotfix. Two related flaws were patched at the same time: CVE-2026-62144 (CVSS 9.3), which also allows unauthenticated attackers to run administrative commands remotely, and CVE-2026-62145 (CVSS 7.5), which lets a low-privilege user escalate to root-level control.
What to do: If your organisation runs Check Point Security Management, apply the July 22 Jumbo hotfix immediately. Restrict Management Server access to trusted IP addresses only, and place it behind a firewall rather than exposing it directly to the internet.
Sources

