hacker-news · Crawled Jul 23, 2026
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
6 IoCs
Read original article ↗
AI Summary
Check Point has patched multiple critical vulnerabilities in its Security Management and Multi-Domain Security Management products, including CVE-2026-16232, an authentication bypass flaw under active exploitation. The vulnerability allows unauthenticated remote attackers to obtain full administrative access to the SmartConsole, enabling modification of security policies and configurations. Exploitation requires internet-accessible management interfaces without IP restrictions, and CISA has added the flaw to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch by July 25, 2026.
AI-extracted · verify before operational use