Close Menu
NCIJ Network |NCIJ Network |
    What's Hot

    Worley takes pre-FEED role on Roman goddess-named Dutch North Sea CCS project

    July 23, 2026

    5 Quotes on Raw Milk From Raw Farm Owner Mark McAfee — ProPublica

    July 23, 2026

    In a fractious, divided world, I think I know why Pride is the hottest show in town | Emma Brockes

    July 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Worley takes pre-FEED role on Roman goddess-named Dutch North Sea CCS project
    • 5 Quotes on Raw Milk From Raw Farm Owner Mark McAfee — ProPublica
    • In a fractious, divided world, I think I know why Pride is the hottest show in town | Emma Brockes
    • Did anti-migration buoys close port in Laredo, Texas?
    • Teenage girl and woman die after group gets into difficulties in sea off Essex beach | Essex
    • Who is Miatta Fahnbulleh, the radical-thinking new UK energy secretary? | Politics
    • Burnham offers 20% cut in business rates for pubs, clubs and live music in England – UK politics live | Politics
    • My Week of Transparent Living With Apple’s ‘More Clear’ Liquid Glass Setting
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network |NCIJ Network |
    Thursday, July 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network |NCIJ Network |
    Home»Cybersecurity

    New Check Point Zero-Day Vulnerability Exploited in the Wild

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 23, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Check Point has notified customers that a critical zero-day vulnerability discovered recently in its products has been exploited in the wild.

    The exploited vulnerability is tracked as CVE-2026-16232 and it affects the cybersecurity company’s Security Management and Multi-Domain Management products. 

    The flaw has been described as an authentication bypass issue that allows an attacker to obtain an application login token. The token can then be used to log in via the SmartConsole with full administrator privileges, and make changes to the security policy and configuration. 

    “Check Point confirmed that this vulnerability has been observed in the wild, affecting a limited number of customers whose Management environments were directly exposed to the Internet without IP restrictions,” Check Point said.

    The security firm has released patches and mitigations, and made available indicators of compromise (IoCs) for the attacks exploiting CVE-2026-16232. Targeted customers have been privately notified.

    CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday, instructing federal agencies to address it by July 25. 

    Advertisement. Scroll to continue reading.

    This is the third Check Point vulnerability added to CISA’s KEV list, after CVE-2026-50751, which attackers exploited as a zero-day in May, and CVE-2024-24919, which threat actors leveraged in 2024. 

    In addition to CVE-2026-16232, Check Point’s latest updates patch CVE-2026-62144, a critical authentication bypass and privilege escalation flaw affecting Security Management and Multi-Domain Management, and CVE-2026-62145, a high-severity local privilege escalation affecting Firewall, Multi-Domain Management, and Multi-Domain Log Server products. 

    All three vulnerabilities were discovered internally by Check Point, but an analysis revealed that CVE-2026-16232 had already been exploited as a zero-day. 

    It’s unclear who is behind the latest attacks, but the Qilin ransomware group was recently observed targeting Check Point appliances. 

    Related: Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

    Related: Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

    Related: SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

    check Exploited Point Vulnerability wild ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

    Adobe Chrome extension flaw let sites access private WhatsApp chats

    Anthropic Releases Claude Security Plugin for Claude Code in Beta: A Multi-Agent Vulnerability Scanner That Runs in Your Terminal

    Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

    GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

    New InfraTrust report reveals infrastructure flaws admins should patch first

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Worley takes pre-FEED role on Roman goddess-named Dutch North Sea CCS project

    July 23, 2026

    5 Quotes on Raw Milk From Raw Farm Owner Mark McAfee — ProPublica

    July 23, 2026

    In a fractious, divided world, I think I know why Pride is the hottest show in town | Emma Brockes

    July 23, 2026

    Did anti-migration buoys close port in Laredo, Texas?

    July 23, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Worley takes pre-FEED role on Roman goddess-named Dutch North Sea CCS project

    July 23, 2026

    5 Quotes on Raw Milk From Raw Farm Owner Mark McAfee — ProPublica

    July 23, 2026

    In a fractious, divided world, I think I know why Pride is the hottest show in town | Emma Brockes

    July 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.