Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
ID: 303e1918-c99d-55b8-a84c-efb5411c0c5f
STIX ID: report--303e1918-c99d-55b8-a84c-efb5411c0c5f
Feed Name: The Hacker News
Check Point released patches for multiple critical vulnerabilities in Security Management and Multi-Domain Management products—most notably CVE-2026-16232, an authentication bypass (CVSS 9.3) allowing unauthenticated remote attackers to obtain admin tokens and modify policies. The vendor reported active limited exploitation, provided six IoCs (IP addresses), recommended a July 22 jumbo hotfix and network access restrictions for Management, and CISA added the flaw to its KEV catalog requiring federal fixes by July 25, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
