Check Point sells firewalls for a living. hackers got admin on it before there was a patch

A broken identity check let attackers skip the login screen entirely — and Check Point found out because someone was already inside.

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVE-2026-16232 is a CVSS 9.3 authentication bypass in Check Point SmartConsole (Security Management Server and Multi-Domain Server/MDS).

The short version

It lets an unauthenticated attacker who can reach the Management Server obtain a valid application login token and log in with full administrator rights.

The short version

Check Point confirmed it was exploited as a zero-day against a small number of customers before the July 22, 2026 patch shipped.

The short version

Versions R77.30 through R82.10 are all in scope; fixed in Jumbo Hotfix Take 36+ (R82.10), Take 118+ (R82), and Take 158+ (R81.20) — R77.30 through R81.10 are end-of-support with no fix.

The short version

Rapid7 published a technical root-cause analysis and a working proof-of-concept on July 28, meaning unpatched systems are now a far easier target than they were a week ago.

How to check if you were already hit

Check Point's own advisory lists concrete indicators from confirmed exploitation: search your Management Server audit logs for 'Authentication method: application token' entries you don't recognize,…

Aliteq

Read the full story

Check Point sells firewalls for a living. hackers got admin on it before there was a patch

Read the full story on Aliteq