Hackers exploit a critical Check Point flaw to hijack management servers

Attackers are actively exploiting a critical flaw in Check Point's security management software that lets them bypass the login entirely and seize full administrative control of the servers that run corporate firewalls. Check Point disclosed the vulnerability, tracked as CVE-2026-16232, on 22 July and confirmed it is already being used in the wild against what it describes as a small number of customers.

Rated a critical 9.1, the bug is an authentication bypass in the SmartConsole login process. An unauthenticated attacker who can reach the management server over the network can obtain a valid application login token and log in with full administrator rights, no password required. From there they can rewrite security policies, change administrator permissions, tamper with VPN settings and disable logging.

Why a management server is such a prize

A Security Management Server sits at the top of the trust hierarchy in a Check Point deployment. Compromise it and an attacker effectively controls every firewall gateway it manages. As the researchers at Rapid7 note, that makes this far more consequential than a single-device bug: policy changes, tampered VPN configurations and silenced monitoring can all follow from one login.

What is affected

The flaw affects Check Point Security Management and Multi-Domain Management. Check Point released Jumbo Hotfixes on 22 July: R82.10 is fixed in Take 36, R82 in Take 118 and R81.20 in Take 158. Older branches including R81.10, R81, R80.30 and earlier have no specified fix. The same advisory also patches CVE-2026-62144, another critical management authentication bypass, and CVE-2026-62145, a high-severity local privilege escalation in the GaiaOS WebUI, though neither of those is known to be exploited yet. Smart-1 Cloud customers are already protected, per the vendor.

What you should do

CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog the same day, setting a remediation deadline of 25 July and giving organizations just three days to act. Administrators should install the latest Jumbo Hotfix on an emergency basis rather than waiting for a normal patch cycle. Where the fix cannot be applied at once, Check Point advises restricting Trusted Clients to specific IP addresses, firewalling management access and keeping implied rules for control connections enabled. Because exploitation predates the patch, Rapid7 urges teams to hunt for signs of compromise even after updating, reviewing administrator, SmartConsole, API and application-token activity and searching logs for the published indicators. Check Point has released six IPs tied to observed exploitation, including 151[.]241[.]99[.]207, 158[.]62[.]198[.]182 and 194[.]213[.]18[.]137.

This is not the first Check Point product under active attack this year. In June, a critical authentication bypass in Check Point's Remote Access VPN was exploited in the wild and added to the CISA KEV list, and CISA has been steadily flagging edge and management appliances, including a SharePoint flaw earlier this month.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions