Check Point Fixes SmartConsole Bypass Under Attack
Check Point has urgently released updates to fix multiple security flaws, notably addressing a critical vulnerability in SmartConsole. This flaw, identified as CVE-2026-16232 with a CVSS score of 9.3, is actively exploited and allows unauthenticated remote attackers to gain full admin access by obtaining a login token. The successful exploitation of this vulnerability requires internet access to the Management Server’s IP, with no restriction on Trusted Clients. Check Point reported that a limited number of customers have been targeted and directly informed. Affected products include Security Management Server and Multi-Domain Security Management Server across several versions. Additional vulnerabilities, CVE-2026-62144 and CVE-2026-62145, were also addressed. Check Point urges administrators to update systems with the latest hotfixes and configure firewall rules to limit access to trusted sources. For further details on how Check Point fixes SmartConsole vulnerabilities, visit the complete article at the provided link below.
Check Point patches actively exploited SmartConsole authentication bypass flaw
