CVE-2026-16232: Check Point SmartConsole Login Process Actively Exploited and More
Check Point has published three new security advisories addressing flaws in Security Management Server (SMS), Multi-Domain Management (MDM), and other Gaia-related components. The highest-priority issue, CVE-2026-16232 (CVSS 9.1), is an actively exploited authentication bypass affecting Check Point SmartConsole in SMS and MDM products. CVE-2026-16232 was published on July 22nd, 2026, and added to CISA’s Known Exploited Vulnerabilities (KEV) list the same day. The other newly disclosed flaws are CVE-2026-62144 (CVSS 9.1), an authentication bypass and privilege escalation in SMS and MDM, and CVE-2026-62145 (CVSS 7.5) affecting the GaiaOS WebUI management interface of Check Point’s Firewall, MDM, Multi-Domain Log Server.

Start Your Free Trial
The OPENVAS ENTERPRISE FEED includes a remote banner version check to identify potentially vulnerable instances of Check Point Gaia OS that may host affected components. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.
A Risk Assessment of Check Point’s July 2026 Security Update
According to Check Point, exploitation of CVE-2026-16232 only affected a very small number of customers that exposed management servers directly to the internet without IP restrictions. The vulnerabilities are high risk because they affect administrative control paths used to configure security policies, objects, gateways, permissions, and monitoring.
Check Point’s Security Management Server (SMS) manages one security-management domain. SMS sits above the gateways in the control hierarchy stores, objects and policies, and distributes them to managed Security Gateways. Multi-Domain Management (MDM) is the large-scale alternative to a single Security Management Server. It provides isolated management environments for different customers, business units, regions, or security zones.
SmartConsole is the GUI used to connect to and manage SMS, and Security Management Servers manage Security Gateways and monitor security events. Gaia Portal is the web-based interface for Gaia OS, and Check Point says most system configuration tasks can be performed through it.
CVE-2026-16232: Actively Exploited SmartConsole Authentication Bypass
CVSS 9.1 · CriticalActively exploitedIn CISA KEV
An improper authentication vulnerability [CWE-287] in the Check Point SmartConsole login process of SMS and MDM products. CVE-2026-16232 allows a remote, unauthenticated attacker to obtain an application login token and use it to authenticate with full administrative privileges. Remote exploitation requires access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Successful exploitation allows the attacker to modify security policies and configurations.
Other CVEs From Check Point’s July 2026 Advisories
Check Point’s July 2026 security advisories also disclosed two additional CVEs:
The two additional CVEs disclosed in Check Point’s July 2026 advisories, each shown with its CVSS severity band and EPSS exploitation-probability score
A critical improper authentication [CWE-287] flaw affecting Check Point SMS and MDM. The flaw allows a remote, unauthenticated attacker to execute administrative commands on the Management Server and potentially execute commands on managed Security Gateways. Exploitation requires network access to a Management Server that does not restrict Trusted Clients.
A high-severity improper privilege management [CWE-269] flaw in Check Point Gaia Portal. Exploitation requires an authenticated account with read-only Gaia Portal privileges. A successful attacker could execute commands with root privileges, potentially gaining complete control of the affected system.
Affected Products and Mitigation for Check Point Security Management and Gaia OS
The direct remediation path is to apply the appropriate Jumbo Hotfix for the affected component’s current version of Gaia OS. For Check Point SMS, the relevant fixes are R81.20 Jumbo Hotfix Take 158, R82 Jumbo Hotfix Take 118, and R82.10 Jumbo Hotfix Take 36. These hotfixes address the CVEs discussed above, as well as CVE-2026-31431 (CVSS 7.8, aka Copy Fail), CVE-2026-43284 (CVSS 8.8), CVE-2026-43500 (CVSS 7.8, aka Dirty Frag), CVE-2026-46300 (CVSS 7.8, aka Fragnesia), and more. Patch prioritization should focus on SMS and MDM deployments that are reachable from the internet and do not use Trusted Clients restrictions or IP restrictions.
Summary
Check Point issued three new security advisories in July 2026 that disclose two Critical vulnerabilities in Security Management Server and one High-severity Gaia Portal privilege-escalation flaw[1][2][3]. CVE-2026-16232 allows full administrative access on Security Management infrastructure and is known to be actively exploited.
Start Your Free Trial
The OPENVAS ENTERPRISE FEED includes a remote banner version check to identify potentially vulnerable instances of Check Point Gaia OS that may host affected components. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s IT infrastructure.
Joseph has had a varied and passionate background in IT and cyber security since the late 1980s. His early technical experience included working on an IBM PS/2, assembling PCs and programming in C++.
He also pursued academic studies in computer and systems engineering, anthropology and an MBA in technology forecasting.
Joseph has worked in data analytics, software development and, in particular, enterprise IT security. He specialises in vulnerability management, encryption and penetration testing.



