Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical SmartConsole Vulnerability Patched by Check Point

Critical SmartConsole Vulnerability Patched by Check Point

Posted on July 23, 2026 By CWS

Check Point has issued security patches to rectify several vulnerabilities affecting its Security Management and Multi-Domain Management (MDSM) products. Among these is a critical flaw actively exploited in the field, necessitating immediate attention.

Details of the Critical Vulnerability

The primary security issue, designated as CVE-2026-16232 with a CVSS score of 9.3, is an authentication bypass vulnerability. This flaw affects the Check Point SmartConsole login mechanism, permitting remote attackers without authentication to acquire an application login token. This access could lead to full administrative control, enabling the modification of security policies and configurations.

For successful exploitation, attackers require internet access to the Management Server’s IP address, and the system must be configured without restrictions on Trusted Clients. Lotem Finkelstein, Check Point’s Vice President of Research, acknowledged that a limited number of customers have been impacted, and they have been informed accordingly. However, the specifics of these attacks remain undisclosed.

Additional Vulnerabilities and Recommendations

Beyond CVE-2026-16232, Check Point addressed two more vulnerabilities. CVE-2026-62144, another critical authentication bypass with a CVSS score of 9.3, allows unauthorized administrative command execution on the Management Server. Additionally, CVE-2026-62145, with a CVSS score of 7.5, involves improper privilege management in the Gaia Portal. This flaw lets authenticated users with read-only privileges execute commands as root.

These vulnerabilities affect versions R77.30 through R82.10. Users are urged to implement the July 22 Jumbo hotfix, limit Trusted Clients to specific IP addresses, and secure Management access with Firewall protection. CISA has added these flaws to its Known Exploited Vulnerabilities catalog, mandating fixes by July 25, 2026.

Indicators of Compromise and Security Measures

Check Point has released several Indicators of Compromise (IoCs) linked to the exploited vulnerabilities. These include IP addresses such as 151.241.99[.]207 and 192.142.10[.]99. Organizations should monitor network traffic for these IoCs and take appropriate action if detected.

In conclusion, applying the provided patches and following the recommended security measures are critical steps to mitigate the potential risks posed by these vulnerabilities. Organizations must remain vigilant and proactive in securing their systems against such threats.

The Hacker News Tags:authentication bypass, Check Point, CISA, CVE-2026-16232, CVE-2026-62144, CVE-2026-62145, Cybersecurity, Gaia Portal, IOC, Multi-Domain Management, network security, security patch, SmartConsole, Vulnerability

Post navigation

Previous Post: Urgent Warning: Check Point Vulnerability Exploited

Related Posts

Malicious npm Packages Exploit PostCSS Tools for Windows RAT Malicious npm Packages Exploit PostCSS Tools for Windows RAT The Hacker News
Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability The Hacker News
VirusTotal Finds 44 Undetected SVG Files Used to Deploy Base64-Encoded Phishing Pages VirusTotal Finds 44 Undetected SVG Files Used to Deploy Base64-Encoded Phishing Pages The Hacker News
How Ineffective Triage Heightens Business Risks How Ineffective Triage Heightens Business Risks The Hacker News
New Fluent Bit Flaws Expose Cloud to RCE and Stealthy Infrastructure Intrusions New Fluent Bit Flaws Expose Cloud to RCE and Stealthy Infrastructure Intrusions The Hacker News
ENCFORGE Ransomware Hits AI Files in Langflow Attack ENCFORGE Ransomware Hits AI Files in Langflow Attack The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical SmartConsole Vulnerability Patched by Check Point
  • Urgent Warning: Check Point Vulnerability Exploited
  • US Alerts on Iranian Cyber Threat to Industrial Control Systems
  • Anthropic Debuts AI-Powered Code Security Plugin
  • Iranian Hackers Prepare for Potential Cyber Disruption

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical SmartConsole Vulnerability Patched by Check Point
  • Urgent Warning: Check Point Vulnerability Exploited
  • US Alerts on Iranian Cyber Threat to Industrial Control Systems
  • Anthropic Debuts AI-Powered Code Security Plugin
  • Iranian Hackers Prepare for Potential Cyber Disruption

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark