Close Menu
    What's Hot

    Opinion | How Trump and His Allies Can Corrupt the Midterms

    Should Travelers Give Up on Summer in Western Europe Because of the Heat?

    ServiceNow bets $40 million on Indian banking software specialist to expand its financial services push

    Facebook X (Twitter) Instagram
    Trending
    • Opinion | How Trump and His Allies Can Corrupt the Midterms
    • Should Travelers Give Up on Summer in Western Europe Because of the Heat?
    • ServiceNow bets $40 million on Indian banking software specialist to expand its financial services push
    • How to be a bull on the S&P 500
    • Cobalt Miners News For The Month Of July 2026
    • Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
    • The U.S. is building its laser dome—one contract at a time
    • The Next Big Tests for the Left: Michigan, Wisconsin and Minnesota
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

    adminBy adminJuly 23, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 23, 2026Vulnerability / Network Security

    Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

    Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild.

    The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

    “Successful exploitation allows the attacker to modify security policies and security configurations,” according to a description of the flaw in CVE.org. “Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients.”

    Cybersecurity

    Lotem Finkelstein, vice president of research at Check Point, said the company is aware of a small number of customers being targeted by this flaw, and that it has already notified them. It did not disclose the nature of the attacks or when they were discovered.

    “This only affects a very specific configuration – when Management is exposed directly to the internet without IP restrictions,” Finkelstein added.

    The cybersecurity vendor has shared the below indicators of compromise (IoCs) associated with the activity –

    • 151.241.99[.]207
    • 151.241.99[.]233
    • 158.62.198[.]182
    • 192.142.10[.]99
    • 139.28.37[.]250
    • 194.213.18[.]137

    Patches have also been released for two other flaws –

    • CVE-2026-62144 (CVSS score: 9.3) – An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management that allows an unauthenticated remote attacker to execute administrative commands on the Management Server, including run-script and exec-command on Security Gateway.
    • CVE-2026-62145 (CVSS score: 7.5) – An improper privilege management vulnerability in Check Point Gaia Portal that allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

    Like in the case of CVE-2026-16232, successful exploitation of CVE-2026-62144 requires management access without Firewall protection or no restrictions on Trusted Clients (GUI clients). All three issues impact the following versions –

    • R77.30
    • R80
    • R80.10
    • R80.20
    • R80.30
    • R81
    • R81.10
    • R81.20
    • R82
    • R82.10
    Cybersecurity

    Customers are recommended to apply the July 22 Jumbo hotfix, limit Trusted Clients (GUI clients) to trusted IP addresses/subnets, secure Management access with Firewall, and restrict access to trusted IP addresses.

    The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by July 25, 2026.

    access Admin allowing check Exploited flaw Full Patches Point SmartConsole
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleThe U.S. is building its laser dome—one contract at a time
    Next Article Cobalt Miners News For The Month Of July 2026
    admin
    • Website

    Related Posts

    Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

    July 23, 2026

    OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark

    July 23, 2026

    Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

    July 22, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Opinion | How Trump and His Allies Can Corrupt the Midterms

    Should Travelers Give Up on Summer in Western Europe Because of the Heat?

    ServiceNow bets $40 million on Indian banking software specialist to expand its financial services push

    How to be a bull on the S&P 500

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by