news.mlab.sh
Back to the feed
vulnerability

New Check Point Zero-Day Vulnerability Exploited in the Wild

Critical
Summary

A critical zero-day vulnerability in Check Point’s Security Management and Multi-Domain Management products has been actively exploited in the wild. The flaw allows attackers to gain administrator-level access, and Check Point has released patches and provided indicators of compromise to affected customers, with CISA urging federal agencies to address the issue by July 25th.

Check Point has alerted its customers to a significant security issue: a recently discovered zero-day vulnerability within its Security Management and Multi-Domain Management products is currently being exploited. This vulnerability, identified as CVE-2026-16232, allows attackers to bypass authentication and obtain an application login token, subsequently granting them full administrator privileges through the SmartConsole. Check Point confirmed that this exploitation has been observed in the wild, impacting a limited number of customers whose Management environments were directly exposed to the internet without IP restrictions. The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) catalog, directing federal agencies to remediate the issue by July 25th. This is not the first Check Point vulnerability to be added to CISA’s KEV list; CVE-2026-50751 was exploited as a zero-day in May, and CVE-2024-24919 was leveraged in 2024. Furthermore, the Qilin ransomware group has recently been linked to targeting Check Point appliances. The vulnerabilities include CVE-2026-62144, a critical authentication bypass and privilege escalation flaw, and CVE-2026-62145, a high-severity local privilege escalation affecting Firewall, Multi-Domain Management, and Multi-Domain Log Server products.

Read the full article at SecurityWeek