Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
WiliRGasparetto
MVP Diamond
MVP Diamond

CVE-2026-16232: Active Exploitation Requires Immediate Management Plane Remediation

CVE-2026-16232: Active Exploitation Requires Immediate Management Plane Remediation

On July 22, 2026, Check Point published an important security update addressing multiple vulnerabilities affecting Security Management, Multi-Domain Management, Security Gateways, and related components.

The most urgent issue is CVE-2026-16232, an authentication bypass involving SmartConsole login with an application token.

Check Point confirmed that this vulnerability has been observed in the wild, affecting a handful of customers whose Management environments were directly exposed to the Internet without IP restrictions.

July 2026 Security Update

CVE Description CVSS Affected Products Active Exploitation
CVE-2026-16232 Authentication bypass with SmartConsole login using an application token 9.3 Security Management and Multi-Domain Management Yes
CVE-2026-62144 Management authentication bypass and privilege escalation 9.3 Security Management and Multi-Domain Management No exploitation reported
CVE-2026-62145 Local privilege escalation in Gaia Portal 7.5 Firewall, Multi-Domain Management, and Multi-Domain Log Server No exploitation reported

 

Affected versions include:

  • R81.10

  • R81.20

  • R82

  • R82.10

  • Older versions are also impacted

Why This Is Critical

The Management Server is not simply another administrative system.

It controls critical security functions such as:

  • Security policies

  • Administrator permissions

  • Managed gateways

  • VPN configurations

  • Threat Prevention settings

  • Policy installation

  • Logging and monitoring

A vulnerability affecting the Management Plane can undermine the trust model of the entire security architecture.

Even organizations whose Management Servers are not directly exposed to the Internet should not postpone remediation. Network restrictions reduce exposure, but they do not remove the vulnerable code.

Immediate Actions

Check Point recommends that customers:

  1. Install the latest Jumbo Hotfix released on July 22, 2026.

  2. Restrict SmartConsole Trusted Clients to approved IP addresses or subnets.

  3. Protect Management access with a firewall.

  4. Avoid direct Internet exposure of Security Management systems.

  5. Verify that implied rules for control connections are enabled and correctly restricted.

  6. Review administrator, SmartConsole, API, application-token, policy-change, and policy-install activity.

  7. Search relevant logs for the published indicators of compromise.

Published IP indicators:

151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137

An IoC match should trigger investigation, but the absence of these addresses does not prove that an environment was not affected.

Mitigation Is Not Remediation

Restricting Trusted Clients and protecting Management access are essential containment measures.

However, they must not replace installation of the security update.

The correct response sequence is:

Reduce exposure
      ↓
Install the Jumbo Hotfix
      ↓
Review for indicators of compromise
      ↓
Validate Management access and operations
      ↓
Continue monitoring

After installation, organizations should confirm:

  • The correct Jumbo Hotfix Take is installed

  • SmartConsole access is limited to authorized sources

  • Management High Availability is healthy, where applicable

  • Policy installation works correctly

  • Administrative accounts and application tokens are valid

  • Temporary access rules have been removed

  • Logging and monitoring remain operational

SecureKnowledge References

  • sk185169 — CVE-2026-16232

  • sk185152 — CVE-2026-62144

  • sk185153 — CVE-2026-62145

Official Advisory

https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-...

The key lesson is clear:

Management infrastructure must be treated as Tier-0 security infrastructure.

Do not expose it directly to the Internet, limit administrative access, install the security update, and validate the environment after remediation.

How quickly can your organization assess exposure, deploy an emergency Jumbo Hotfix, and confirm that the Management Plane remains trusted?

(2)
22 Replies
jorgeluiznim
Advisor

Great article, @WiliRGasparetto! Thanks for the heads-up.

We are already taking action on our end: around 60 appliances (Quantum Force 3920 and 3950 models) are undergoing updates and bench validation before we deploy them to the customer environment.

Onward! 🚀

WiliRGasparetto
MVP Diamond
MVP Diamond

Excellent, @jorgeluiznim ; the remediation measures are extremely relevant and necessary at this moment.

Duane_Toler
MVP Silver
MVP Silver

I just posted a link to my Ansible playbook that will do the log hunting for you from Check Point's suggested query, and save results to CSV for easy review.

https://community.checkpoint.com/t5/API-CLI-Discussion/Log-hunting-playbook-for-CVE-2026-16232/m-p/2...

Stay safe everyone!

 

--
Ansible for Check Point APIs series: https://www.youtube.com/@EdgeCaseScenario and Substack
WiliRGasparetto
MVP Diamond
MVP Diamond

Cool, I'll give it a read. Thanks for your cooperation.

Mattias_Jansson
Collaborator

Nice.

Question: Is it best practise to restrict access to a gateway with both firewall rules and gaia - host access, or is it enough with only firewall rules and keep default gaia - host access from any?

emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

If it's a firewall then all inbound access must be accepted by the policy, so good policy controls are sufficient. If it's a management server then you need host access controls if you don't have the management server properly isolated by other access control nodes on the network. 

WiliRGasparetto
MVP Diamond
MVP Diamond

Let me better understand your question: by "Gaia," do you mean the Management Server?

Mattias_Jansson
Collaborator

No, the question was about the firewall. 
The allowed-client setting can be configured on both the Management and Firewall servers.

Emmas answered it above, so I am a happy user! 🙂

0 Kudos
Alex-
MVP Silver
MVP Silver

Security works in layers, though.

I don't see the harm for a firewall in restricting access in the policy *and* with the allowed hosts. There are situations in which the policy might be unloaded or some change causing the policy to allow access to the system, for whatever reason.

WiliRGasparetto
MVP Diamond
MVP Diamond

Okay, feel free to reach out if you have any further questions.

AttiqRahman786
MVP Silver
MVP Silver

Thanks for this.

WiliRGasparetto
MVP Diamond
MVP Diamond

Your Welcome

genisis__
MVP Silver
MVP Silver

I've noted the versions affected run from R81.10, however no new Jumbo has been released for this version with the fixes, do we know if this coming?
Additionally do we know what the status is with Embedded Gaia R82.00.10?  Will a new build be released, if this is affected?

Another question - will the ISO images be updated to include the Jumbos considering these are high CVSS rated issues?

0 Kudos
WiliRGasparetto
MVP Diamond
MVP Diamond

1. Jumbo Status for R81.10
As of now, there is no official record of a new Jumbo Hotfix released for R81.10 containing specific fixes for CVEs CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145. There is also no public announcement regarding the release date of a new Jumbo containing these fixes.

Recommendations:

Continue monitoring the Check Point support portal and relevant SKs for Jumbo updates.
If your organization is exposed to these CVEs, it is recommended to open a support case to obtain information on interim hotfixes or the expected release timeline.
2. Embedded Gaia R82.00.10
There is no public confirmation that Embedded Gaia R82.00.10 is affected by these CVEs, nor is there an announcement regarding a new build to address them. In previous instances, Check Point has typically released updated builds for Gaia Embedded when critical vulnerabilities are identified.

Recommendations:

Periodically check the support portal and SKs for updated builds.
If exposure is suspected, contact support for clarification and potential workarounds.
3. ISO Updates with Jumbos
For high-severity vulnerabilities (high CVSS), Check Point generally updates official ISO images to include the latest Jumbos; however, this may not happen immediately after the Jumbo is released. The ISO update cycle can vary.

Best Practice:

After installing the ISO, always apply the latest available Jumbo Hotfix before putting the system into production.
Keep an eye out for official announcements regarding new ISOs with integrated Jumbos.

If I hear of any updates on this, I'll let you know here.

Best

WiliRGasparetto
MVP Diamond
MVP Diamond

If you have any further questions, just let me know.

garrett_masters
Explorer

Has Check Point confirmed if Smart One Cloud is or is not affected? I haven't been able to find any Check Point specific documentation on that piece, even though this R7 article claims it's not affected. https://www.rapid7.com/blog/post/etr-cve-2026-16232-critical-check-point-smartconsole-authentication...

"Smart-1 Cloud customers are already protected according to Check Point."

0 Kudos
_Val_
Admin
Admin

If you have any concerns, open a TAC case to get an official answer. However, for the specific CVE in question, the system is only vulnerable if it is not patched and open to any client to access.

0 Kudos
garrett_masters
Explorer

Thanks. TAC got back to me yesterday and confirmed S1C has already been patched.

herman142376
Explorer

great post.

WiliRGasparetto
MVP Diamond
MVP Diamond

thk's

herman142376
Explorer

you welcome

Mark89
Explorer

well done

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events