preloader

· digital-security check-point vulnerability-management firewall europe incident-response

Check Point Patches a Firewall Management Flaw Attackers Were Already Using to Get Full Admin Access

Source: Help Net Security / Check Point Security Advisory

Check Point disclosed and patched CVE-2026-16232 on July 22, a critical authentication bypass in SmartConsole, the management interface administrators use to configure and monitor Check Point firewalls. The flaw carries a CVSS score of 9.1 and was already being exploited against a small number of customers before the fix shipped, which is the detail that turns this from a routine patch into an emergency one.

What the flaw actually allows

The vulnerability sits in the SmartConsole login process and is classified as improper authentication. An unauthenticated remote attacker who can reach the Management Server IP address can obtain a valid application login token and authenticate to the server with full administrative privileges, no credentials required. From there, an attacker can read and rewrite firewall security policies, disable rules, open holes in network segmentation, or quietly weaken logging before moving on to whatever sits behind the firewall.

Who is exposed

Affected versions include R81.10, R81.20, R82 and R82.10, along with older releases that are no longer supported. Hotfixes are available for R81.20, R82 and R82.10 through the July 22 Jumbo hotfix. Exploitation requires network reachability to the Management Server, so the risk is concentrated in environments where Trusted Clients, the GUI clients permitted to reach SmartConsole, are not restricted to a defined set of IP addresses or subnets. Many organisations set Trusted Clients broadly during initial deployment and never revisit it, which is exactly the gap this flaw exploits.

What to do this week

Check Point’s own guidance is direct: apply the hotfix now, then separately restrict Trusted Clients to known administrative IP ranges and put the Management Server itself behind a firewall rather than relying on SmartConsole authentication as the only gate. CISA has already added CVE-2026-16232 to its Known Exploited Vulnerabilities catalogue with a July 25 remediation deadline for US federal agencies, a strong signal of how seriously the exploitation reports are being taken. European organisations, which are not bound by that deadline but face the same active attackers, should not wait for a compliance mandate to move at the same speed.

If your firewall management infrastructure has not had its access controls reviewed recently, or you want an independent check on whether your Check Point, or any other vendor’s, management plane is reachable from more places than it should be, contact Excello Digital. We help European IT teams close exactly this kind of gap before it becomes an incident report.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!