Check Point Software Technologies has disclosed three security vulnerabilities affecting its Security Management and Multi-Domain Management products, including a critical authentication bypass flaw that has already been exploited in the wild.
The disclosure came through a jumbo hotfix released as part of the company’s Frontier AI Readiness Program, an initiative combining security hardening improvements with proactive vulnerability discovery.
Critical Check Point Flaw
Lotem Finkelstein confirmed the findings emerged from a routine BLAST review of the company’s internal red-teaming and vulnerability-hunting process.
The most severe issue, tracked as CVE-2026-16232, carries a CVSS score of 9.3 and allows attackers to bypass SmartConsole login authentication using an application token.
This vulnerability affects Security Management and Multi-Domain Management servers running R81.10, R81.20, R82, and R82.10, with older versions also impacted.
Check Point confirmed active exploitation, though it emphasized the attack surface is narrow: only management servers directly exposed to the internet without IP restrictions are vulnerable.
All affected customers have reportedly been notified directly, and Smart-1 Cloud customers are confirmed to already be protected.
Additional Vulnerabilities Patched
Two related flaws were also addressed in the same update:
- CVE-2026-62144 (CVSS 9.3): A management authentication bypass and privilege escalation vulnerability affecting the same product line and versions. No in-the-wild exploitation has been observed.
- CVE-2026-62145 (CVSS 7.5): A local privilege escalation flaw in the GaiaOS WebUI affecting Firewall, Multi-Domain Management, and Multi-Domain Log Server products. This flaw also has no reported active exploitation.
All three vulnerabilities span the same affected version range: R81.10, R81.20, R82, and R82.10, along with earlier unsupported releases.
Indicators of Compromise
A list of IP addresses observed in connection with exploitation attempts:
- 151.241.99[.]207
- 151.241.99[.]233
- 158.62.198[.]182
- 192.142.10[.]99
- 139.28.37[.]250
- 194.213.18[.]137
Security teams should check logs for connections from these addresses to management interfaces.
Mitigation
Check Point is urging all customers to install the jumbo hotfix immediately and follow established security best practices. Specific recommendations include:
- Restrict Trusted Clients (GUI clients) to explicitly trusted IP addresses or subnets.
- Firewall-protect management access, limiting connections to trusted sources only.
- Verify that implied rules for control connections remain enabled to prevent unauthorized access paths.
Organizations running exposed management servers without IP-based access controls should treat this as a priority patch, given the confirmed exploitation of CVE-2026-16232.
This underscores a broader industry theme: internet-facing management interfaces remain a high-value target for attackers, and even mature security vendors are not immune to authentication bypass flaws in their own control-plane infrastructure.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.