Check Point patches two critical management server flaws
Check Point has published updates for Security Management and Multi-Domain Management addressing CVE-2026-16232, an authentication bypass in the SmartConsole login process. The flaw can let an unauthenticated remote attacker obtain a login token and gain full administrative access to the Management Server. The vendor states the flaw has been observed exploited against a small number of customers, who have been notified. The July update also fixes CVE-2026-62144, which similarly allows an unauthenticated attacker to bypass authentication and run administrative commands on the Management Server, and by extension commands on managed Security Gateways. Both require network access to a Management Server not adequately protected by firewall rules or Trusted Client restrictions. Affected versions include R81.10, R81.20, R82 and R82.10, along with some older releases.
What this means for you if you operate Check Point management servers
The management server is where your firewall policy is decided. If an attacker gains administrative access there, this is no longer about a single rule being bypassed. As we see it, it is about control of your entire internal perimeter.
If your organisation is in scope of NIS2, this system sits high on any criticality assessment you make. We think an actively exploited weakness in it should be treated as an incident on your side. That should stand until you have documented otherwise.
Berigo recommends
- Install the July update on all affected management servers, ahead of ordinary change windows.
- Verify the management server is not reachable from the internet, and restrict access to trusted IP addresses and subnets using Trusted Clients.
- Review login logs and administrator accounts for the period before patching, looking for token issuance and policy changes you do not recognise.
- Clarify with your service provider who actually owns patching of this component if operations are outsourced.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch