logo

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

ID: 303e1918-c99d-55b8-a84c-efb5411c0c5f

STIX ID: report--303e1918-c99d-55b8-a84c-efb5411c0c5f

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: [email protected] (The Hacker News)

...
...

Check Point released patches for multiple critical vulnerabilities in Security Management and Multi-Domain Management products—most notably CVE-2026-16232, an authentication bypass (CVSS 9.3) allowing unauthenticated remote attackers to obtain admin tokens and modify policies. The vendor reported active limited exploitation, provided six IoCs (IP addresses), recommended a July 22 jumbo hotfix and network access restrictions for Management, and CISA added the flaw to its KEV catalog requiring federal fixes by July 25, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.