AI Stories on SHORT INFO are generated & curated with AI
unverified 29 Jul, 15:43

Critical Check Point SmartConsole flaw let attackers seize full admin access before a patch existed

A critical authentication bypass in Check Point's SmartConsole login process let unauthenticated attackers seize full administrative control of exposed security management servers. Check Point $CHKP found the flaw already being exploited against a small number of customers before

A critical authentication bypass, tracked as CVE-2026-16232 and scored 9.3 on the CVSS severity scale, affected the login process of Check Point's SmartConsole admin panel. The flaw let an unauthenticated remote attacker obtain an application login token and authenticate with full administrative privileges on a Security Management Server or Multi-Domain Security Management Server, exploitable only when the server is exposed directly to the internet without IP restrictions on trusted clients. Check Point $CHKP discovered the bug during its own internal review and found it already being exploited against a small number of customers, who were notified before a fix shipped. Ten software versions were affected, from R77.30 through R82.10. Check Point released patches on July 22, 2026, alongside fixes for two related flaws, CVE-2026-62144 (also CVSS 9.3) and CVE-2026-62145 (CVSS 7.5). The US Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by July 25, 2026. Source: The Hacker News, BleepingComputer.

#cyber
Published on
FacebookYouTubeBlueskyX