Close Menu
NCIJ Network |NCIJ Network |
    What's Hot

    After shocking quarter, IBM insists that AI isn’t killing the mainframe

    July 23, 2026

    Best Open Speech Recognition (ASR) Models in 2026: WER, Languages, Latency, and License Compared

    July 23, 2026

    Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

    July 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • After shocking quarter, IBM insists that AI isn’t killing the mainframe
    • Best Open Speech Recognition (ASR) Models in 2026: WER, Languages, Latency, and License Compared
    • Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
    • Bitcoin consolidates below $66,000 as a 13% July recovery runs out of steam
    • New cancer strategy could stop tumors before resistance takes hold
    • Worley takes pre-FEED role on Roman goddess-named Dutch North Sea CCS project
    • 5 Quotes on Raw Milk From Raw Farm Owner Mark McAfee — ProPublica
    • In a fractious, divided world, I think I know why Pride is the hottest show in town | Emma Brockes
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network |NCIJ Network |
    Thursday, July 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network |NCIJ Network |
    Home»Cybersecurity

    Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 23, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 23, 2026Vulnerability / Network Security

    Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild.

    The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

    “Successful exploitation allows the attacker to modify security policies and security configurations,” according to a description of the flaw in CVE.org. “Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients.”

    Cybersecurity

    Lotem Finkelstein, vice president of research at Check Point, said the company is aware of a small number of customers being targeted by this flaw, and that it has already notified them. It did not disclose the nature of the attacks or when they were discovered.

    “This only affects a very specific configuration – when Management is exposed directly to the internet without IP restrictions,” Finkelstein added.

    The cybersecurity vendor has shared the below indicators of compromise (IoCs) associated with the activity –

    • 151.241.99[.]207
    • 151.241.99[.]233
    • 158.62.198[.]182
    • 192.142.10[.]99
    • 139.28.37[.]250
    • 194.213.18[.]137

    Patches have also been released for two other flaws –

    • CVE-2026-62144 (CVSS score: 9.3) – An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management that allows an unauthenticated remote attacker to execute administrative commands on the Management Server, including run-script and exec-command on Security Gateway.
    • CVE-2026-62145 (CVSS score: 7.5) – An improper privilege management vulnerability in Check Point Gaia Portal that allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

    Like in the case of CVE-2026-16232, successful exploitation of CVE-2026-62144 requires management access without Firewall protection or no restrictions on Trusted Clients (GUI clients). All three issues impact the following versions –

    • R77.30
    • R80
    • R80.10
    • R80.20
    • R80.30
    • R81
    • R81.10
    • R81.20
    • R82
    • R82.10
    Cybersecurity

    Customers are recommended to apply the July 22 Jumbo hotfix, limit Trusted Clients (GUI clients) to trusted IP addresses/subnets, secure Management access with Firewall, and restrict access to trusted IP addresses.

    The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by July 25, 2026.

    access Admin allowing check Exploited Flaw Full Patches Point SmartConsole
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

    New Check Point Zero-Day Vulnerability Exploited in the Wild

    AliExpress gets record €550m fine from EU for allowing sale of illegal products

    Adobe Chrome extension flaw let sites access private WhatsApp chats

    Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

    GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    After shocking quarter, IBM insists that AI isn’t killing the mainframe

    July 23, 2026

    Best Open Speech Recognition (ASR) Models in 2026: WER, Languages, Latency, and License Compared

    July 23, 2026

    Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

    July 23, 2026

    Bitcoin consolidates below $66,000 as a 13% July recovery runs out of steam

    July 23, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    After shocking quarter, IBM insists that AI isn’t killing the mainframe

    July 23, 2026

    Best Open Speech Recognition (ASR) Models in 2026: WER, Languages, Latency, and License Compared

    July 23, 2026

    Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

    July 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.