Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
Reported exploitedCheck Point Security ManagementMulti-Domain Security ManagementOur summary
A critical authentication bypass vulnerability (CVE-2026-16232) in Check Point Security Management and Multi-Domain Security Management is currently being exploited by attackers. This flaw allows unauthenticated users to gain admin-level access through SmartConsole, enabling them to modify security policies and configurations. Check Point has issued hotfixes for supported versions—R81.20, R82, and R82.10—and advised customers to restrict access to trusted IPs if immediate patching isn't possible. CISA has added this flaw to its Known Exploited Vulnerabilities catalog, requiring U.S. federal agencies to act by July 25.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.