Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical SmartConsole Vulnerability Patched by Check Point

Critical SmartConsole Vulnerability Patched by Check Point

Posted on July 23, 2026 By CWS

Check Point has issued security patches to rectify several vulnerabilities affecting its Security Management and Multi-Domain Management (MDSM) products. Among these is a critical flaw actively exploited in the field, necessitating immediate attention.

Details of the Critical Vulnerability

The primary security issue, designated as CVE-2026-16232 with a CVSS score of 9.3, is an authentication bypass vulnerability. This flaw affects the Check Point SmartConsole login mechanism, permitting remote attackers without authentication to acquire an application login token. This access could lead to full administrative control, enabling the modification of security policies and configurations.

For successful exploitation, attackers require internet access to the Management Server’s IP address, and the system must be configured without restrictions on Trusted Clients. Lotem Finkelstein, Check Point’s Vice President of Research, acknowledged that a limited number of customers have been impacted, and they have been informed accordingly. However, the specifics of these attacks remain undisclosed.

Additional Vulnerabilities and Recommendations

Beyond CVE-2026-16232, Check Point addressed two more vulnerabilities. CVE-2026-62144, another critical authentication bypass with a CVSS score of 9.3, allows unauthorized administrative command execution on the Management Server. Additionally, CVE-2026-62145, with a CVSS score of 7.5, involves improper privilege management in the Gaia Portal. This flaw lets authenticated users with read-only privileges execute commands as root.

These vulnerabilities affect versions R77.30 through R82.10. Users are urged to implement the July 22 Jumbo hotfix, limit Trusted Clients to specific IP addresses, and secure Management access with Firewall protection. CISA has added these flaws to its Known Exploited Vulnerabilities catalog, mandating fixes by July 25, 2026.

Indicators of Compromise and Security Measures

Check Point has released several Indicators of Compromise (IoCs) linked to the exploited vulnerabilities. These include IP addresses such as 151.241.99[.]207 and 192.142.10[.]99. Organizations should monitor network traffic for these IoCs and take appropriate action if detected.

In conclusion, applying the provided patches and following the recommended security measures are critical steps to mitigate the potential risks posed by these vulnerabilities. Organizations must remain vigilant and proactive in securing their systems against such threats.

The Hacker News Tags:authentication bypass, Check Point, CISA, CVE-2026-16232, CVE-2026-62144, CVE-2026-62145, Cybersecurity, Gaia Portal, IOC, Multi-Domain Management, network security, security patch, SmartConsole, Vulnerability

Post navigation

Previous Post: Urgent Warning: Check Point Vulnerability Exploited
Next Post: Check Point Zero-Day Vulnerability Actively Exploited

Related Posts

Dangerous npm Package Steals macOS Credentials Dangerous npm Package Steals macOS Credentials The Hacker News
Prioritization, Validation, and Outcomes That Matter Prioritization, Validation, and Outcomes That Matter The Hacker News
Microsoft Defender Zero-Day Exploits Unpatched Microsoft Defender Zero-Day Exploits Unpatched The Hacker News
Security Patches Released by Over 60 Software Vendors Security Patches Released by Over 60 Software Vendors The Hacker News
HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution The Hacker News
Automating Data Transfers: A National Security Necessity Automating Data Transfers: A National Security Necessity The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • KARR Bluetooth Flaw Threatens Millions of Cars with Hacking Risk
  • Check Point Zero-Day Vulnerability Actively Exploited
  • Critical SmartConsole Vulnerability Patched by Check Point
  • Urgent Warning: Check Point Vulnerability Exploited
  • US Alerts on Iranian Cyber Threat to Industrial Control Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • KARR Bluetooth Flaw Threatens Millions of Cars with Hacking Risk
  • Check Point Zero-Day Vulnerability Actively Exploited
  • Critical SmartConsole Vulnerability Patched by Check Point
  • Urgent Warning: Check Point Vulnerability Exploited
  • US Alerts on Iranian Cyber Threat to Industrial Control Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark