- Products
- Learn
- Local User Groups
- Partners
- More
Simplify Admin Operations with R82.20
Wed, 19 August @ 5pm CET/11am EDT
The industry's first AI Network Firewall
Securing AI traffic, everywhere
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
READY OR NOT: Securing the AI Enterprise
AI Research & Threat Landscape
CheckMates Go:
That's Serious Stuff!
On July 22, 2026, Check Point published an important security update addressing multiple vulnerabilities affecting Security Management, Multi-Domain Management, Security Gateways, and related components.
The most urgent issue is CVE-2026-16232, an authentication bypass involving SmartConsole login with an application token.
Check Point confirmed that this vulnerability has been observed in the wild, affecting a handful of customers whose Management environments were directly exposed to the Internet without IP restrictions.
| CVE | Description | CVSS | Affected Products | Active Exploitation |
|---|---|---|---|---|
| CVE-2026-16232 | Authentication bypass with SmartConsole login using an application token | 9.3 | Security Management and Multi-Domain Management | Yes |
| CVE-2026-62144 | Management authentication bypass and privilege escalation | 9.3 | Security Management and Multi-Domain Management | No exploitation reported |
| CVE-2026-62145 | Local privilege escalation in Gaia Portal | 7.5 | Firewall, Multi-Domain Management, and Multi-Domain Log Server | No exploitation reported |
Affected versions include:
R81.10
R81.20
R82
R82.10
Older versions are also impacted
The Management Server is not simply another administrative system.
It controls critical security functions such as:
Security policies
Administrator permissions
Managed gateways
VPN configurations
Threat Prevention settings
Policy installation
Logging and monitoring
A vulnerability affecting the Management Plane can undermine the trust model of the entire security architecture.
Even organizations whose Management Servers are not directly exposed to the Internet should not postpone remediation. Network restrictions reduce exposure, but they do not remove the vulnerable code.
Check Point recommends that customers:
Install the latest Jumbo Hotfix released on July 22, 2026.
Restrict SmartConsole Trusted Clients to approved IP addresses or subnets.
Protect Management access with a firewall.
Avoid direct Internet exposure of Security Management systems.
Verify that implied rules for control connections are enabled and correctly restricted.
Review administrator, SmartConsole, API, application-token, policy-change, and policy-install activity.
Search relevant logs for the published indicators of compromise.
Published IP indicators:
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
An IoC match should trigger investigation, but the absence of these addresses does not prove that an environment was not affected.
Restricting Trusted Clients and protecting Management access are essential containment measures.
However, they must not replace installation of the security update.
The correct response sequence is:
Reduce exposure
↓
Install the Jumbo Hotfix
↓
Review for indicators of compromise
↓
Validate Management access and operations
↓
Continue monitoring
After installation, organizations should confirm:
The correct Jumbo Hotfix Take is installed
SmartConsole access is limited to authorized sources
Management High Availability is healthy, where applicable
Policy installation works correctly
Administrative accounts and application tokens are valid
Temporary access rules have been removed
Logging and monitoring remain operational
sk185169 — CVE-2026-16232
sk185152 — CVE-2026-62144
sk185153 — CVE-2026-62145
The key lesson is clear:
Management infrastructure must be treated as Tier-0 security infrastructure.
Do not expose it directly to the Internet, limit administrative access, install the security update, and validate the environment after remediation.
How quickly can your organization assess exposure, deploy an emergency Jumbo Hotfix, and confirm that the Management Plane remains trusted?
Great article, @WiliRGasparetto! Thanks for the heads-up.
We are already taking action on our end: around 60 appliances (Quantum Force 3920 and 3950 models) are undergoing updates and bench validation before we deploy them to the customer environment.
Onward! 🚀
Excellent, @jorgeluiznim ; the remediation measures are extremely relevant and necessary at this moment.
I just posted a link to my Ansible playbook that will do the log hunting for you from Check Point's suggested query, and save results to CSV for easy review.
Stay safe everyone!
Cool, I'll give it a read. Thanks for your cooperation.
Nice.
Question: Is it best practise to restrict access to a gateway with both firewall rules and gaia - host access, or is it enough with only firewall rules and keep default gaia - host access from any?
If it's a firewall then all inbound access must be accepted by the policy, so good policy controls are sufficient. If it's a management server then you need host access controls if you don't have the management server properly isolated by other access control nodes on the network.
Let me better understand your question: by "Gaia," do you mean the Management Server?
No, the question was about the firewall.
The allowed-client setting can be configured on both the Management and Firewall servers.
Emmas answered it above, so I am a happy user! 🙂
Security works in layers, though.
I don't see the harm for a firewall in restricting access in the policy *and* with the allowed hosts. There are situations in which the policy might be unloaded or some change causing the policy to allow access to the system, for whatever reason.
Okay, feel free to reach out if you have any further questions.
Thanks for this.
Your Welcome
I've noted the versions affected run from R81.10, however no new Jumbo has been released for this version with the fixes, do we know if this coming?
Additionally do we know what the status is with Embedded Gaia R82.00.10? Will a new build be released, if this is affected?
Another question - will the ISO images be updated to include the Jumbos considering these are high CVSS rated issues?
1. Jumbo Status for R81.10
As of now, there is no official record of a new Jumbo Hotfix released for R81.10 containing specific fixes for CVEs CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145. There is also no public announcement regarding the release date of a new Jumbo containing these fixes.
Recommendations:
Continue monitoring the Check Point support portal and relevant SKs for Jumbo updates.
If your organization is exposed to these CVEs, it is recommended to open a support case to obtain information on interim hotfixes or the expected release timeline.
2. Embedded Gaia R82.00.10
There is no public confirmation that Embedded Gaia R82.00.10 is affected by these CVEs, nor is there an announcement regarding a new build to address them. In previous instances, Check Point has typically released updated builds for Gaia Embedded when critical vulnerabilities are identified.
Recommendations:
Periodically check the support portal and SKs for updated builds.
If exposure is suspected, contact support for clarification and potential workarounds.
3. ISO Updates with Jumbos
For high-severity vulnerabilities (high CVSS), Check Point generally updates official ISO images to include the latest Jumbos; however, this may not happen immediately after the Jumbo is released. The ISO update cycle can vary.
Best Practice:
After installing the ISO, always apply the latest available Jumbo Hotfix before putting the system into production.
Keep an eye out for official announcements regarding new ISOs with integrated Jumbos.
If I hear of any updates on this, I'll let you know here.
Best
If you have any further questions, just let me know.
Has Check Point confirmed if Smart One Cloud is or is not affected? I haven't been able to find any Check Point specific documentation on that piece, even though this R7 article claims it's not affected. https://www.rapid7.com/blog/post/etr-cve-2026-16232-critical-check-point-smartconsole-authentication...
"Smart-1 Cloud customers are already protected according to Check Point."
If you have any concerns, open a TAC case to get an official answer. However, for the specific CVE in question, the system is only vulnerable if it is not patched and open to any client to access.
Thanks. TAC got back to me yesterday and confirmed S1C has already been patched.
great post.
thk's
you welcome
well done
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 156 | |
| 105 | |
| 15 | |
| 12 | |
| 11 | |
| 10 | |
| 8 | |
| 7 | |
| 6 | |
| 6 |
Tue 18 Aug 2026 @ 01:00 PM (BRT)
IA: a nova linha de frente do endpoint - Todo ataque tem um antes, um durante e depois.Thu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IAThu 20 Aug 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #11: SD-WAN Simplicity and Scalability in 2026Tue 18 Aug 2026 @ 01:00 PM (BRT)
IA: a nova linha de frente do endpoint - Todo ataque tem um antes, um durante e depois.Thu 20 Aug 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #11: SD-WAN Simplicity and Scalability in 2026Thu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 25 Aug 2026 @ 05:00 PM (CEST)
The State of Ransomware Q2 2026: This Quarter's Trends, and Their Impact on Your DefensesThu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IAThu 20 Aug 2026 @ 06:00 PM (COT)
Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de SeguridadAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY