Do this first: install the latest Jumbo Hotfix on your Check Point Security Management and Multi-Domain Management servers. One hotfix, released 22 July, covers all three flaws. That is the whole vendor-side fix; the rest is yours.
This is three flaws that chain, not one. CVE-2026-16232 (the exploited one) is an authentication bypass giving an unauthenticated attacker full admin on the management console. CVE-2026-62144 is a second unauthenticated bypass that also runs commands on the managed Security Gateways — the actual firewalls. CVE-2026-62145 turns a read-only appliance user into root. Together: an internet request to command execution across the whole firewall estate.
The exploited one is the least dangerous of the three. Only CVE-2026-16232 has been seen in attacks, so it sets the urgency — but CVE-2026-62144 reaches further and shares the same precondition; it just hasn't been caught yet. Patch the KEV-listed CVE and stop, and you have fixed the smallest problem. All three need only the internet-facing, unrestricted-Trusted-Clients configuration that Check Point says defined the handful of victims. Management on an internal network, behind IP restrictions, was never exposed.
Patching does not undo what an attacker already did. If your management was exposed, the fix shuts the door but leaves behind altered policy, new accounts, pushed gateway commands and tokens. Check Point published six attacker IPs to hunt with, and Rapid7 is explicit that patching alone is not remediation.
Why now. Check Point disclosed three flaws on 22 July and shipped a Jumbo Hotfix the same day. It found them internally, then discovered one — CVE-2026-16232 — had already been used as a zero-day against a few customers whose management was internet-exposed without IP restrictions. CISA added it to KEV on 22 July, federal deadline 25 July. It is ACT because it is exploited, KEV-listed, and hands over the device that governs the perimeter — and because the same release carries an unexploited bypass that reaches from that console down to the firewalls.
| Product | Package | Carries |
|---|---|---|
| Security Management / Multi-Domain Management / Gaia — R81.10, R81.20, R82, R82.10 (older versions also affected) | not established | resolve via vendor advisory before deployment |
Also inside: Both critical flaws are management-plane authentication bypasses with the same precondition. CVE-2026-16232 makes SmartConsole issue an application login token to someone who never logged in; the token is accepted as full admin. CVE-2026-62144 lets an unauthenticated attacker run admin commands on the Management Server and — the part that matters — push commands to the managed Security Gateways via run-script and exec-command. A management server exists to configure the firewalls beneath it; a flaw that turns that against you reaches every gateway, not just the console. CVE-2026-62145 adds a Gaia Portal escalation: a read-only user runs commands as root. All three need the same two conditions — management reachable from the internet, and an unrestricted Trusted Clients list — and neither is the intended configuration.
Then. Check whether it applies to you. Is your Security or Multi-Domain Management server reachable from the internet, and is Trusted Clients restricted to known addresses? If management is internal and Trusted Clients is locked down, none of the three was exploitable against you, and the hotfix is routine. Patch all three, not just the exploited one — the single hotfix closes the set, and the unexploited CVE-2026-62144 is the one that reaches your gateways. Confirm the exact Jumbo take for your version in sk185169 and sk185152. If management was exposed, hunt — patching is not remediation. An attacker who got in keeps what they changed: admin accounts, altered policy, pushed gateway commands, tokens. Review administrator, SmartConsole, API and application-token activity, check gateways for unexpected command execution, and search for the six IPs below. Treat console policy and gateway configuration as in question until the logs clear them. Then close the exposure for good: management off the public internet, Trusted Clients restricted, the management interface behind a firewall rule.
We rate this ACT on exploitation and KEV listing, carried by CVE-2026-16232. Because the exposure precondition runs against Check Point's own guidance, most estates were never reachable, and it is fair to say so — this is not a drop-everything event for a shop whose management sits where it should. We treat the release as one ACT unit rather than ranking the CVEs, because one hotfix fixes all of them and splitting them tempts a reader to patch the exploited one and defer the rest — the one mistake this release makes easy.
The exploited flaw is the least dangerous of the three, so treat the release as one unit rather than ranking the CVEs.
Basis. Only CVE-2026-16232 is confirmed exploited, but CVE-2026-62144 carries the same 9.1 vector, the same unauthenticated precondition, and reaches further — to command execution on the managed gateways — while CVE-2026-62145 adds root on the appliance. One hotfix fixes all three. A reader who patches only the KEV-listed CVE fixes the entry that has been seen and leaves the deeper reach open.
What would lower this. If CVE-2026-62144's gateway reach turns out to depend on a management feature most estates disable, the 'patch all three or miss the worst' framing overstates the shared exposure. The gated per-CVE detail in sk185152 would settle it; we have read the public summaries, not that detail.
For most Check Point operators this is a configuration audit, not an emergency — but only a check tells you which group you are in.
Basis. Check Point limits the in-the-wild exploitation to internet-exposed management without IP restrictions, and all three flaws share that precondition, which runs against the vendor's own deployment guidance. An estate that keeps management internal and restricts Trusted Clients was not reachable through any of them.
What would lower this. The reassurance depends on the preconditions holding in live configuration, not on the architecture diagram. Shadow exposure — a management interface published through a forgotten NAT rule, a Trusted Clients list widened for a project — is exactly what it misses. If you cannot confirm the preconditions from live config, treat yourself as potentially exposed until you can.
Two unauthenticated bypasses put an attacker on the management plane; one reaches down to the firewalls it manages; a third takes the appliance to root. The hotfix cuts the way in at step 2 — but step 5 is what an attacker already inside leaves behind, which the patch does not undo.
Attacker IPs Check Point published for CVE-2026-16232. Search management and administrator logs for these, especially if management was internet-facing. Brackets are defanging; remove before use.
| Type | Value |
|---|---|
ipv4 | 151.241.99[.]207 |
ipv4 | 151.241.99[.]233 |
ipv4 | 158.62.198[.]182 |
ipv4 | 192.142.10[.]99 |
ipv4 | 139.28.37[.]250 |
ipv4 | 194.213.18[.]137 |
Edge and security appliances as a share of CISA KEV additions, by year (2026 is a partial year, to 22 July)
| 2024 | 20% | |
|---|---|---|
| 2025 | 19% | |
| 2026 YTD | 15% |
Every few weeks an appliance gets a critical CVE and the industry reacts as though it were new. By our count of CISA's KEV catalogue it is the opposite of new: security and edge appliances have been roughly one in five exploited vulnerabilities in 2024, in 2025, and so far in 2026 — a steady share, not a rising one (the 2026 dip is dilution by a flood of web-app and CMS listings, not fewer appliances; the absolute count holds near forty a year). And the way in is rarely clever: about a quarter of those appliance flaws are authentication bypasses, the login broken rather than an exploit chain built. This Check Point release is that pattern in one advisory — two unauthenticated bypasses of the management plane, both 9.1, both carrying the identical CVSS vector as CVE-2026-0257, the Palo Alto GlobalProtect bypass exploited two months earlier. If one in five has been a security appliance three years running, that is not an incident to react to, it is an architecture to plan for: keep the management plane off the public internet, restrict who can reach it, and patch these vendors on the clock you use for your most exposed servers.
| Source | Admiralty | Used for |
|---|---|---|
| https://support.checkpoint.com/results/sk/sk185169/ | A1 | PRIMARY: vendor KB for CVE-2026-16232 — affected products and versions, the application-token bypass, the Jumbo Hotfix remedy, the Trusted Clients / management-exposure precondition. Read 2026-07-24 |
| https://support.checkpoint.com/results/sk/sk185152/ | A1 | Vendor KB for CVE-2026-62144, 'Management Authentication Bypass and Privilege Escalation' — unauthenticated admin command execution on the Management Server and on managed gateways via run-script and exec-command |
| https://blog.checkpoint.com/security/security-advisory-action-required-active- | A1 | Vendor advisory, read in full. Exploitation limited to internet-exposed management without IP restrictions; the six attacker IPs; mitigations; three vulnerabilities disclosed, one exploited; Jumbo Hotfix 22 July 2026 |
| https://nvd.nist.gov/vuln/detail/CVE-2026-16232 | A1 | Authoritative description and CVSS v3.1 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N); full admin and policy modification; published 2026-07-22, Analyzed |
| https://nvd.nist.gov/vuln/detail/CVE-2026-62144 | A1 | Authoritative description and CVSS v3.1 9.1, identical vector to CVE-2026-16232: unauthenticated admin command execution on the Management Server, possibly on managed gateways; same precondition. Read 2026-07-24 |
| https://nvd.nist.gov/vuln/detail/CVE-2026-62145 | A1 | Authoritative description and CVSS v3.1 7.5 HIGH: Gaia Portal read-only user can execute commands as root. Read 2026-07-24 |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog | A1 | KEV read 2026-07-24 (catalog 2026.07.23): CVE-2026-16232 dateAdded 2026-07-22, dueDate 2026-07-25, CWE-287, ransomware Unknown. Also the basis for the trend count (11 of 75 additions in the last 90 days were edge/security appliances) |
| https://www.rapid7.com/blog/post/etr-cve-2026-16232-critical-check-point-smart | A2 | Read in full. Mechanism; precondition; that mitigations do not address the vulnerability; post-patch hunt guidance |
| https://www.securityweek.com/new-check-point-zero-day-vulnerability-exploited- | B2 | Corroborates internal discovery of three flaws with CVE-2026-16232 found exploited as a zero-day; exploitation limited to internet-exposed management; KEV addition and 25 July deadline |
| https://thehackernews.com/2026/07/check-point-patches-exploited.html | B2 | Independent reporting on all three CVEs and the fix, including the gateway reach of CVE-2026-62144 and the Gaia root escalation of CVE-2026-62145 |