{"id":14511,"date":"2026-07-23T10:03:36","date_gmt":"2026-07-23T10:03:36","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/07\/23\/cisa-warns-of-check-point-authentication-vulnerability-actively-exploited-in-the-wild\/"},"modified":"2026-07-23T10:03:36","modified_gmt":"2026-07-23T10:03:36","slug":"cisa-warns-of-check-point-authentication-vulnerability-actively-exploited-in-the-wild","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/07\/23\/cisa-warns-of-check-point-authentication-vulnerability-actively-exploited-in-the-wild\/","title":{"rendered":"CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild"},"content":{"rendered":"<p>    CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p class=\"wp-block-paragraph\">The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical <a href=\"https:\/\/cybersecuritynews.com\/palo-alto-vulnerability-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">authentication vulnerability<\/a> in Check Point SmartConsole that is actively being exploited in the wild, prompting organizations to take immediate defensive action.<\/p>\n<p class=\"wp-block-paragraph\">Tracked as CVE-2026-16232, the flaw affects Check Point Security Management and Multi-Domain Management platforms and carries a CVSS score of 9.3, indicating severe risk.<\/p>\n<p class=\"wp-block-paragraph\">The vulnerability stems from improper authentication (CWE-287) and allows an unauthenticated remote attacker to obtain an application login token. Once acquired, the token can be used to gain full administrative access to affected systems, effectively bypassing standard authentication controls.<\/p>\n<h2 id=\"h-check-point-authentication-vulnerability-exploited\" class=\"wp-block-heading\"><strong>Check Point Authentication Vulnerability Exploited<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">According to Check Point, the issue was identified during an internal BLAST (Business Logic Attack Surface Testing) review conducted as part of its Frontier AI Readiness Program.<\/p>\n<p class=\"wp-block-paragraph\">While analyzing multiple vulnerabilities, researchers discovered that CVE-2026-16232 had already been exploited in real-world attacks, impacting a limited number of customers.<\/p>\n<p class=\"wp-block-paragraph\">The exploitation appears to be limited to environments where management interfaces are directly exposed to the internet without IP-based access restrictions.<\/p>\n<p class=\"wp-block-paragraph\">This exposure condition significantly increases the attack surface, allowing threat actors to remotely target vulnerable management systems.<\/p>\n<p class=\"wp-block-paragraph\">Once compromised, attackers could potentially modify security policies, deploy malicious configurations, or pivot deeper into enterprise networks. Given the administrative level of access granted through the exploit, the impact could extend to full infrastructure compromise.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CISA\u2019s inclusion of the vulnerability<\/a> in its Known Exploited Vulnerabilities (KEV) catalog underscores the urgency of patching and mitigation. Organizations using affected versions, including R81.10, R81.20, R82, and R82.10, are strongly advised to take immediate action. Older versions may also be impacted, further broadening the potential risk landscape.<\/p>\n<p class=\"wp-block-paragraph\">In addition to CVE-2026-16232, <a href=\"https:\/\/blog.checkpoint.com\/security\/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Check Point disclosed two other<\/a> high-severity vulnerabilities as part of the same advisory. CVE-2026-62144 involves another authentication bypass and privilege escalation issue within management systems, also rated 9.3, although it has not been observed in active exploitation.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-62145 affects GaiaOS WebUI and allows local privilege escalation with a CVSS score of 7.5. While these vulnerabilities are not currently exploited, they contribute to the overall risk profile and should be addressed alongside the primary flaw.<\/p>\n<p class=\"wp-block-paragraph\">Security teams are encouraged to review logs and network telemetry for any communication with these indicators of compromise as part of incident detection and response efforts.<\/p>\n<p class=\"wp-block-paragraph\">To mitigate the risk, Check Point and CISA recommend restricting SmartConsole and management access to trusted IP addresses only, ensuring that management interfaces are not exposed to the public internet.<\/p>\n<p class=\"wp-block-paragraph\">Organizations should also enforce firewall protections, verify that implied rules for control connections are enabled, and limit GUI client access to authorized networks.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">IP Address<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">151.241.99[.]207<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Observed in exploitation attempts<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">151.241.99[.]233<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Observed in exploitation attempts<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">158.62.198[.]182<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Suspicious activity linked to attacks<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">192.142.10[.]99<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Potential attacker infrastructure<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">139.28.37[.]250<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Associated with malicious traffic<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">194.213.18[.]137<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Observed targeting vulnerable systems<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">The most critical step, however, is the immediate deployment of the latest Jumbo Hotfix released on July 22, 2026. This update includes security patches and hardening improvements designed to remediate the vulnerability and strengthen overall system resilience.<\/p>\n<p class=\"wp-block-paragraph\">The incident highlights the ongoing risks associated with exposed management interfaces and the importance of layered security controls.<\/p>\n<p class=\"wp-block-paragraph\">As attackers continue to target high-value administrative systems, proactive patching, strict access controls, and continuous monitoring remain essential to defending enterprise environments against evolving threats.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)\"><strong><strong>The Privilege Paths Attackers See That You Don\u2019t: BeyondTrust Pathfinder Platform Does It for You -&gt;\u00a0<a href=\"https:\/\/www.beyondtrust.com\/products\/identity-security-insights\/assessment?utm_source=cybersecuritynews&amp;utm_medium=web&amp;utm_campaign=prospecting&amp;campid=701Vw00000aN1mhIAC\">Get Free Identity Security Assessment<\/a><\/strong><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/check-point-vulnerability-exploited\/\">CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/check-point-vulnerability-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical authentication vulnerability in Check Point SmartConsole that is actively being exploited in the wild, prompting organizations to take immediate defensive action. Tracked as CVE-2026-16232, the flaw affects [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648],"tags":[130],"class_list":["post-14511","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14511"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=14511"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/14511\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=14511"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=14511"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=14511"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}