Check Point warns that a zero-day in its management products — tracked as CVE-2026-16232 — has been exploited in the wild. The flaw enables an authentication bypass that can yield an application session token usable to log into SmartConsole with full administrative privileges, allowing attackers to modify policies and configurations.
Technical details of CVE-2026-16232
The vulnerability affects Check Point Security Management and Multi‑Domain Management appliances. Described by the vendor as an authentication bypass, it allows an attacker to obtain an application token which, once used, grants full administrator access through SmartConsole. Check Point reports observed exploitation against a small number of customers whose Management environments were directly exposed to the Internet without IP restrictions.
Patches, mitigations and indicators provided
Check Point has released patches and mitigation guidance, and published indicators of compromise (IoCs) to help detect attempts to exploit CVE-2026-16232. Impacted customers were notified privately. In addition to this fix, Check Point is issuing updates for two other vulnerabilities affecting other product components: CVE-2026-62144 (authentication bypass and privilege escalation, rated critical) and CVE-2026-62145 (local privilege escalation, rated high).
Government directives and timeline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) catalog and directed federal agencies to remediate the vulnerability by July 25. This is the third Check Point flaw to be added to the KEV list, following CVE-2026-50751 (exploited as a zero-day in May) and CVE-2024-24919 (reported exploitation in 2024).
Threat context and scope
All the vulnerabilities were found internally by Check Point, but analysis indicates CVE-2026-16232 was exploited prior to the public release of a patch. No public attribution has been established for the attacks; however, available evidence shows the Qilin ransomware group has recently targeted Check Point appliances.
Recommended actions
Organizations with management consoles exposed to the public Internet should:
– Apply Check Point’s patches and mitigations immediately.
– Review the IoCs provided by Check Point to hunt for signs of exploitation.
– Check management access logs for suspicious activity or unexpected administrative sessions.
– Restrict network access to management interfaces (e.g., IP allowlists, VPN-only access, firewall rules) to reduce the risk of unauthorized access.
Summary
Check Point urges immediate updates for affected environments and log reviews for indicators of compromise, while authorities are pushing a rapid remediation schedule for government infrastructure. CVE-2026-16232 represents a high-impact zero-day because successful exploitation can yield full SmartConsole administrative control.

