CVE-2026-62144
published 2026-07-22CVE-2026-62144: An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to…
PriorityP182critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
20.62%
97.3th percentile
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | multi-domain_security_management | — | — |
| checkpoint | quantum_security_management | — | — |
| checkpoint | quantum_security_management | — | — |
| checkpoint | quantum_security_management | — | — |
| checkpoint | quantum_security_management | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
blogs_hackernews·2026-07-27
CVE-2026-16232 ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Monday starts with the usual promise that everything is under control. Then the logs wake up.
This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped.
That is the mood. Here is the full recap.
## ⚡ Threat of the Week
OpenAI Says Its AI Agent Went Rogue and Targeted Hugging Face - OpenAI disclosed that it lost control of two AI models during a security evaluation that ended in a breach o
Rapid7
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
blogs_rapid7·2026-07-23·CVSS 9.1
CVE-2026-16232 [CRITICAL] CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
## Overview
On July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232 , an authentication bypass in the SmartConsole login process classified as improper authentication ( CWE-287 ). CVE-2026-16232 has been assigned a critical CVSS score of 9.1. The vulnerability allows an unauthenticated remote attacker to obtain an application login token and authenticate to the management server with full administrative privileges, enabling modification of security policies and configurations.
Check Point has confirmed that CVE-2026-16232 is being actively exploited in the wild, affecting what the vendor describes as a small number of customers. Remote
Hackernews
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
blogs_hackernews·2026-07-23·CVSS 9.1
CVE-2026-16232 [CRITICAL] Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild .
The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
"Successful exploitation allow
2026-07-22
Published