Check Point zero-day CVE-2026-16232 exploited

A Check Point zero-day, CVE-2026-16232, has been used to bypass authentication and obtain admin tokens for Security Management and Multi-Domain Management.

Check Point confirmed that CVE-2026-16232, a critical authentication bypass in its Security Management and Multi-Domain Management products, has been exploited in the wild. The flaw allows an attacker to obtain an application login token that can be used to access SmartConsole with full administrator privileges.

The company reported the exploit affected a limited number of customers whose management interfaces were directly reachable from the public internet without IP restrictions. With a valid token, an attacker can change security policies and configuration settings on affected management servers.

Check Point released software updates and temporary mitigations for CVE-2026-16232 and published indicators of compromise tied to the active exploit. Targeted customers received private notifications and were urged to apply the updates and follow the provided mitigations to limit exposure.

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog and instructed federal agencies to remediate the issue by July 25.

The vendor’s recent patches also address CVE-2026-62144, an authentication bypass and privilege escalation affecting Security Management and Multi-Domain Management, and CVE-2026-62145, a local privilege escalation affecting Firewall, Multi-Domain Management, and Multi-Domain Log Server products. Check Point discovered all three flaws internally, and analysis showed CVE-2026-16232 had been used in targeted attacks before public disclosure.

Security researchers have observed the Qilin ransomware group targeting Check Point appliances recently, but no connection between that activity and the CVE-2026-16232 incidents has been confirmed.

Organizations running affected Check Point components are advised to confirm management interfaces are not exposed to the public internet, install the vendor updates, and review the published indicators of compromise for signs of intrusion.

Articles by this author