Critical Check Point Zero-Day Vulnerability Actively Exploited

www.news4hackers.com-critical-check-point-zero-day-vulnerability-actively-exploited-critical-check-point-zero-day-vulnerability-actively-exploited

Check Point has informed clients that a significant zero-day vulnerability identified in its software has been actively exploited by malicious actors.

Overview of the Vulnerability

The flaw, designated CVE-2026-16232, impacts the company’s Security Management and Multi-Domain Management systems. The issue allows unauthorized access by bypassing authentication mechanisms, enabling attackers to acquire administrative login tokens. These tokens can then be leveraged to access the SmartConsole with full control over security policies and configurations.

Key Details and Impact

Check Point confirmed that the vulnerability has been observed in real-world attacks, affecting a small number of clients with Management systems exposed to the internet without IP-based restrictions. The company has issued patches and provided indicators of compromise (IoCs) to help organizations detect and mitigate potential breaches. Affected customers have been contacted directly.

CISA Involvement and Timeline

The Cybersecurity and Infrastructure Security Agency (CISA) included CVE-2026-16232 in its Known Exploited Vulnerabilities (KEV) catalog on Wednesday, mandating federal agencies to resolve the issue by July 25. This marks the third Check Point vulnerability added to CISA’s list, following CVE-2026-50751, which was exploited as a zero-day in May, and CVE-2024-24919, which was used in 2024.

Additional Vulnerabilities Addressed

In addition to CVE-2026-16232, Check Point’s recent updates address two other flaws: CVE-2026-62144, a critical authentication bypass and privilege escalation vulnerability affecting Security Management and Multi-Domain Management systems, and CVE-2026-62145, a high-severity local privilege escalation flaw impacting Firewall, Multi-Domain Management, and Multi-Domain Log Server products. All three vulnerabilities were identified internally by Check Point, though CVE-2026-16232 was already being exploited in the wild prior to disclosure.

Threat Actors and Mitigation

The perpetrator behind the attacks remains unidentified, but the Qilin ransomware group has been linked to recent targeting of Check Point appliances. The company emphasized the urgency of applying patches and monitoring for signs of compromise. Other vulnerabilities addressed in the latest updates include flaws in Adobe extensions, ServiceNow, and SonicWall, which were exploited before official fixes were released.

Proactive Security Measures

Meanwhile, ongoing threats such as ransomware attacks and data breaches continue to highlight the need for proactive security measures. Organizations are advised to review the provided IoCs, apply available patches, and implement strict access controls to prevent unauthorized exploitation of similar vulnerabilities. The incident underscores the evolving tactics of threat actors and the importance of timely response to emerging threats.

  • CVE-2026-16232: Critical authentication bypass in Security Management and Multi-Domain Management systems
  • CVE-2026-62144: Critical authentication bypass and privilege escalation in Security Management and Multi-Domain Management systems
  • CVE-2026-62145: High-severity local privilege escalation in Firewall, Multi-Domain Management, and Multi-Domain Log Server products



About Author

en_USEnglish