Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
ID: 2302b0b9-c336-5aba-86b1-0cfb7f2ef7e4
STIX ID: report--2302b0b9-c336-5aba-86b1-0cfb7f2ef7e4
Feed Name: Help Net Security
A critical authentication bypass (CVE-2026-16232) in Check Point Security Management/Multi-Domain Management is being actively exploited to obtain full admin SmartConsole access and alter security policy; Check Point released jumbo hotfixes for affected versions, provided mitigation guidance (restrict Trusted Clients and firewall management access) and shared attacker IP addresses, and CISA added the CVE to its Known Exploited Vulnerabilities list with remediation deadlines for federal agencies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
