Overview
On July 22, 2026, Check Point , an authentication bypass in the SmartConsole login process classified as improper authentication ( to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) list of known exploited vulnerabilities (KEV), with a remediation due date of July 25, 2026, giving organizations only three days to respond.
The advisory addresses three vulnerabilities in total:
CVE | CVSS | Description | Affected Products | Exploitation Status |
|---|---|---|---|---|
CVE-2026-16232 | Vendor: 9.3 (Critical) | Authentication bypass via SmartConsole application token | Security Management, Multi-Domain Management | Exploited in the wild |
CVE-2026-62144 | Vendor: 9.3 (Critical) | Management authentication bypass and privilege escalation | Security Management, Multi-Domain Management | No known exploitation |
CVE-2026-62145 | 7.5 (High) | Local privilege escalation in GaiaOS WebUI | Firewall, Multi-Domain Management, Multi-Domain Log Server | No known exploitation |
Compromise of a Security Management Server is particularly consequential because it sits at the top of the trust hierarchy. An attacker with administrative access can modify security policies across managed gateways, alter administrator permissions, manipulate VPN configurations, and potentially disable or tamper with logging and monitoring. According to Check Point's , a critical authentication bypass in Check Point Remote Access VPN, was exploited in the wild and added to the CISA KEV. In May 2024, .
Rapid7 customers
Exposure Command, InsightVM, and Nexpose
Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-16232, CVE-2026-62144, CVE-2026-62145 with authenticated vulnerability checks expected to be available in the 24 July content release.
Indicators of compromise
Check Point has published the following IP addresses associated with observed exploitation of CVE-2026-16232:
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
Per the vendor, the presence of these indicators should prompt investigation, but the absence of these addresses does not confirm that an environment was unaffected.
Updates
July 23, 2026: Initial publication.
SOCIAL SHARE CARD GENERATOR