Check Point patches actively exploited SmartConsole authentication bypass flaw
ID: 8a85dcac-57af-53c4-8934-32afafb8e285
STIX ID: report--8a85dcac-57af-53c4-8934-32afafb8e285
Feed Name: Security Affairs
Check Point released security updates to remediate a critical authentication bypass (CVE-2026-16232, CVSS 9.3) in SmartConsole that is under active exploitation and can allow unauthenticated attackers to obtain a login token and gain full administrative access to Security Management and MDSM servers; the advisory includes identified attacker IPs, affected product versions, recommended mitigations (restrict Trusted Clients, firewall-management access, apply July 22 jumbo hotfix), and notes two additional high-severity CVEs impacting management functionality and Gaia Portal privilege escalation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
