Affected Systems
Check Point Security Management and Multi-Domain Management (MDSM) products: R77.30, R80, R80.10, R80.20, R80.30, R81, R81.10, R81.20, R82, R82.10. Affects SmartConsole login process when Management Server is exposed to internet without IP restrictions on Trusted Clients.
Exploitation Status
Active exploitation confirmed. Check Point reports small number of customers targeted. CISA added CVE-2026-16232 to KEV catalog. Six attacker IP addresses identified: 151.241.99[.]207, 151.241.99[.]233, 158.62.198[.]182, 192.142.10[.]99, 139.28.37[.]250, 194.213.18[.]137.
Business Impact
Unauthenticated remote attacker gains full administrative privileges via login token theft. Attacker can modify security policies, change configurations, and execute administrative commands including run-script and exec-command on Security Gateway. Only exploitable when Management Server has direct internet exposure without Trusted Client IP restrictions—a misconfiguration, but one present in targeted environments. Two additional critical/high flaws (CVE-2026-62144, CVE-2026-62145) patched simultaneously.
Urgency
🔴 Immediate
Recommended Actions
- Apply Check Point July 22 Jumbo hotfix immediately to all affected Security Management and MDSM servers (R77.30 through R82.10)
- Block inbound connections from six known attacker IPs: 151.241.99[.]207, 151.241.99[.]233, 158.62.198[.]182, 192.142.10[.]99, 139.28.37[.]250, 194.213.18[.]137
- Restrict Trusted Clients (GUI clients) to specific trusted IP addresses or subnets—do not allow 0.0.0.0/0
- Place Management Server behind firewall; remove direct internet exposure to Management Server IP address
- Review SmartConsole authentication logs for unauthorized login tokens or administrative actions from July 2026 onward; correlate with IOC list
