INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
SmartConsole Zero-Day Exploit Allows Full Admin Access
| 2026-07-23 08:33 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The Check Point patches actively exploited SmartConsole authentication bypass flaw, a critical vulnerability affecting Security Management and Multi-Domain Security Management servers. The flaw allows unauthenticated remote attackers to execute administrative actions on the management server, including run-script and exec-command operations on security gateways. To mitigate the attack, customers are advised to restrict trusted clients to approved IP addresses only, protect management access with firewall rules, and ensure implied control connection rules are enabled. A July 22 hotfix is also recommended for all affected systems, which includes restricting trusted clients to approved IP addresses or subnets and protecting management access through firewall rules allowing only authorized sources.
Technical Mitigations AI-generated
* Restrict SmartConsole Trusted Clients to trusted IP addresses only (avoid using "Any") and protect Management Server access with firewall rules.
* Ensure implied control connection rules are enabled on the Management Server, which can help prevent unauthorized access.
* Review logs for connections involving known attacker IP addresses to detect potential compromise.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
151.241.•••.•••
158.62.•••.•••
151.241.•••.•••
192.142.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
QilinQilin
CVE-2026-62145CVE-2026-62145
CVE-2026-16232CVE-2026-16232
CVE-2024-24919CVE-2024-24919
CVE-2026-62144CVE-2026-62144
CVE-2026-50751CVE-2026-50751
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
July 22
Threat actors exploited a SmartConsole authentication bypass flaw in R80.30 versions by using the July 22 Jumbo hotfix to gain unauthorized access through restricted Trusted Clients.
Click on any entity below to view its context and source!
organisation
R80
All three issues impact the following versions -
R77.30
R80
R80.10
R80.20
R80.30
R81
R81.10
R81.20
R82
R82.10
Customers are recommended to apply the July 22 Jumbo hotfix, limit Trusted Clients (GUI clients) to trusted IP addresses/subnets, secure Management access with Firewall, and restrict access to trusted IP addresses.
organisation
R80.20
R80.30
All three issues impact the following versions -
R77.30
R80
R80.10
R80.20
R80.30
R81
R81.10
R81.20
R82
R82.10
Customers are recommended to apply the July 22 Jumbo hotfix, limit Trusted Clients (GUI clients) to trusted IP addresses/subnets, secure Management access with Firewall, and restrict access to trusted IP addresses.
Jul 23, 2026
Threat actors exploited a previously unknown vulnerability in Check Point's SmartConsole, allowing them to bypass its authentication mechanisms.
2026/07/23
Check Point released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild.
Click on any entity below to view its context and source!
infrastructure
9.3
Check Point has released
security updates
to fix multiple vulnerabilities, including CVE-2026-16232 (CVSS score of 9.3), a critical authentication bypass flaw affecting Security Management and Multi-Domain Management (MDSM).
The cybersecurity vendor has shared the below indicators of compromise (IoCs) associated with the activity -
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
Patches have also been released for two other flaws -
CVE-2026-62144
(CVSS score: 9.3) -
organisation
Security Management
Check Point has released
security updates
to fix multiple vulnerabilities, including CVE-2026-16232 (CVSS score of 9.3), a critical authentication bypass flaw affecting Security Management and Multi-Domain Management (MDSM).
After gaining access to a vulnerable Security Management Server or Multi-Domain Security Management Server (MDS), attackers can change the security configuration and security policy.
Ravie Lakshmanan
Jul 23, 2026
Vulnerability / Network Security
Check Point has
released
security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come
under active exploitation in the wild
.
organisation
Check Point
Check Point said it is aware of a limited number of customers targeted through CVE-2026-16232 and has already notified the affected organizations.
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel.
"
Lotem Finkelstein, vice president of research at Check Point, said the company is aware of a small number of customers being targeted by this flaw, and that it has already notified them.
financial
04 BOD
While BOD 26-04 applies only to U.S. government agencies, CISA urged all organizations to prioritize patching the CVE-2026-16232 vulnerability to block incoming attacks.
organisation
Check Point SmartConsole
The security flaw, tracked as
CVE-2026-16232
(CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
organisation
GUI
Like in the case of CVE-2026-16232, successful exploitation of CVE-2026-62144 requires management access without Firewall protection or no restrictions on Trusted Clients (GUI clients).
Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel.
“Successful remote exploit requires internet access to the Management Server IP address and no restrictions on Trusted Clients (GUI clients).”
organisation
Security Gateways
Check Point also addressed two additional security vulnerabilities:
CVE-2026-62144
(CVSS score of 9.3): A critical authentication bypass flaw in Security Management and Multi-Domain Security Management that enables unauthenticated remote attackers to execute administrative actions on the Management Server, including
run-script
and
exec-command
operations on Security Gateways.
infrastructure
151.241.99
The cybersecurity vendor has shared the below indicators of compromise (IoCs) associated with the activity -
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
Patches have also been released for two other flaws -
CVE-2026-62144
(CVSS score: 9.3) -
The following attacker IP addresses have been identified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and versions:
Products: Security Management Server, Multi-Domain Security Management Server (MDS)
Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81
infrastructure
158.62.198
The cybersecurity vendor has shared the below indicators of compromise (IoCs) associated with the activity -
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
Patches have also been released for two other flaws -
CVE-2026-62144
(CVSS score: 9.3) -
The following attacker IP addresses have been identified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and versions:
Products: Security Management Server, Multi-Domain Security Management Server (MDS)
Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81
infrastructure
192.142.10
The cybersecurity vendor has shared the below indicators of compromise (IoCs) associated with the activity -
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
Patches have also been released for two other flaws -
CVE-2026-62144
(CVSS score: 9.3) -
The following attacker IP addresses have been identified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and versions:
Products: Security Management Server, Multi-Domain Security Management Server (MDS)
Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81
infrastructure
139.28.37
The cybersecurity vendor has shared the below indicators of compromise (IoCs) associated with the activity -
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
Patches have also been released for two other flaws -
CVE-2026-62144
(CVSS score: 9.3) -
The following attacker IP addresses have been identified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and versions:
Products: Security Management Server, Multi-Domain Security Management Server (MDS)
Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81
infrastructure
194.213.18
The cybersecurity vendor has shared the below indicators of compromise (IoCs) associated with the activity -
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
Patches have also been released for two other flaws -
CVE-2026-62144
(CVSS score: 9.3) -
The following attacker IP addresses have been identified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and versions:
Products: Security Management Server, Multi-Domain Security Management Server (MDS)
Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81
organisation
Multi-Domain Security Management
After gaining access to a vulnerable Security Management Server or Multi-Domain Security Management Server (MDS), attackers can change the security configuration and security policy.
The following attacker IP addresses have been identified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and versions:
Products: Security Management Server, Multi-Domain Security Management Server (MDS)
Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81
organisation
MDS
After gaining access to a vulnerable Security Management Server or Multi-Domain Security Management Server (MDS), attackers can change the security configuration and security policy.
The following attacker IP addresses have been identified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and versions:
Products: Security Management Server, Multi-Domain Security Management Server (MDS)
Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81
organisation
Vulnerability / Network Security
Ravie Lakshmanan
Jul 23, 2026
Vulnerability / Network Security
Check Point has
released
security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come
under active exploitation in the wild
.
organisation
Lotem Finkelstein
"
Lotem Finkelstein, vice president of research at Check Point, said the company is aware of a small number of customers being targeted by this flaw, and that it has already notified them.
organisation
IP
The following attacker IP addresses have been identified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and versions:
Products: Security Management Server, Multi-Domain Security Management Server (MDS)
Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81
"
Admins who can't immediately upgrade to a patched version are advised to follow the
Check Point Hardening Best Practices Guide
, limit Trusted Clients to trusted IP addresses/subnets, and ensure that management access is blocked for non-authorized IP addresses.
"This only affects a very specific configuration - when Management is exposed directly to the internet without IP restrictions," Finkelstein added.
organisation
R80
The following attacker IP addresses have been identified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and versions:
Products: Security Management Server, Multi-Domain Security Management Server (MDS)
Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81
organisation
R80.10
The following attacker IP addresses have been identified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and versions:
Products: Security Management Server, Multi-Domain Security Management Server (MDS)
Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81
organisation
R80.20
The following attacker IP addresses have been identified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and versions:
Products: Security Management Server, Multi-Domain Security Management Server (MDS)
Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81
organisation
R81
The following attacker IP addresses have been identified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and versions:
Products: Security Management Server, Multi-Domain Security Management Server (MDS)
Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81
organisation
Management
"This only affects a very specific configuration - when Management is exposed directly to the internet without IP restrictions," Finkelstein added.
organisation
the Management
“Successful remote exploit requires internet access to the Management Server IP address and no restrictions on Trusted Clients (GUI clients).”
Check Point added that successful exploitation requires no restrictions on Trusted Clients (GUI clients) and the Management Server IP to be exposed to remote access via the Internet.
"Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients.
organisation
Trusted Clients
“Successful remote exploit requires internet access to the Management Server IP address and no restrictions on Trusted Clients (GUI clients).”
Check Point added that successful exploitation requires no restrictions on Trusted Clients (GUI clients) and the Management Server IP to be exposed to remote access via the Internet.
"Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients.
organisation
SmartConsole Trusted Clients
R81.10, R81.20, R82, R82.10
To mitigate the attack, restrict SmartConsole Trusted Clients to trusted IP addresses only (avoid using “Any”), protect Management Server access with firewall rules, and ensure implied control connection rules are enabled.
organisation
Check Point Security Management
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management that allows an unauthenticated remote attacker to execute administrative commands on the Management Server, including run-script and exec-command on Security Gateway.
organisation
CVE-2026-62145
CVE-2026-62145
(CVSS score of 7.5): An improper privilege management issue in the Gaia Portal that allows authenticated users with read-only access to escalate privileges and execute commands as root.
CVE-2026-62145
(CVSS score: 7.5) -
organisation
SmartConsole
Check Point patches actively exploited SmartConsole authentication bypass flaw.
Check Point warns of SmartConsole zero-day exploited in attacks.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Check Point)
organisation
Logs & Monitor / Logs & Events > Audit Logs View
Checking SmartConsole logs for signs of compromise (Check Point)
To verify if a SmartConsole instance has been compromised, admins have to search for the query "Authentication method: application token" in SmartConsole under Logs & Monitor / Logs & Events > Audit Logs View after running the following SmartConsole query:
(src:151.241.99.207 OR dst:151.241.99.207 OR src:151.241.99.233 OR dst:151.241.99.233 OR src:158.62.198.182 OR dst:158.62.198.182 OR src:192.142.10.99 OR dst:192.142.10.99 OR src:139.28.37.250 OR dst:139.28.37.250)
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
CVE.org
"Successful exploitation allows the attacker to modify security policies and security configurations," according to a description of the flaw in CVE.org.
organisation
Gaia Portal
An improper privilege management vulnerability in Check Point Gaia Portal that allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.
Saturday, July 25
Threat actors exploited a SmartConsole authentication bypass flaw in Check Point patches.
Click on any entity below to view its context and source!
general_metric
26 Binding Operational Directive
On Wednesday, the Cybersecurity and Infrastructure Security Agency (CISA) also added the flaw to
its catalog of known exploited vulnerabilities
, ordering U.S. federal agencies to patch vulnerable SmartConsole instances by Saturday, July 25, as mandated by Binding Operational Directive (BOD) 26-04.
July 25, 2026
Threat actors exploited a vulnerability in the SmartConsole authentication system to bypass security controls.
Click on any entity below to view its context and source!
attribution
Known Exploited
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the flaw to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by July 25, 2026.
tactic
T1588.006 - Vulnerabilities
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the flaw to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by July 25, 2026.
attribution
KEV
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the flaw to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by July 25, 2026.
attribution
Federal Civilian Executive Branch
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the flaw to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by July 25, 2026.
attribution
FCEB
The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to
add
the flaw to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary fixes by July 25, 2026.
Tactical Metrics
Metrics
infrastructure
9.3
Software Version
Click for context!
Check Point has released
security updates
to fix multiple vulnerabilities, including CVE-2026-16232 (CVSS score of 9.3), a critical authentication bypass flaw affecting Security Management and Multi-Domain Management (MDSM).
…IoCs) associated with the activity -
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
Patches have also been released for two other flaws -
CVE-2026-62144
(CVSS score: 9.3) -
Metrics
infrastructure
151.241.99
Software Version
The following attacker IP addresses have been identified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following produc…
The cybersecurity vendor has shared the below indicators of compromise (IoCs) associated with the activity -
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
Patches have also bee…
Metrics
infrastructure
158.62.198
Software Version
…ng attacker IP addresses have been identified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and vers…
…s shared the below indicators of compromise (IoCs) associated with the activity -
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
Patches have also been released for two other fl…
Metrics
infrastructure
192.142.10
Software Version
…esses have been identified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and versions:
Products…
…indicators of compromise (IoCs) associated with the activity -
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
Patches have also been released for two other flaws -
CVE-2026-…
Metrics
infrastructure
139.28.37
Software Version
…entified as indicators of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and versions:
Products: Security Managem…
…romise (IoCs) associated with the activity -
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
Patches have also been released for two other flaws -
CVE-2026-62144
(CVSS score…
Metrics
infrastructure
194.213.18
Software Version
…tors of compromise (IoCs):
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
The flaw impacts the following products and versions:
Products: Security Management Server, Multi-…
…IoCs) associated with the activity -
151.241.99[.]207
151.241.99[.]233
158.62.198[.]182
192.142.10[.]99
139.28.37[.]250
194.213.18[.]137
Patches have also been released for two other flaws -
CVE-2026-62144
(CVSS score: 9.3) -
Metrics
financial
4
Bod
While BOD 26-04 applies only to U.S. government agencies, CISA urged all organizations to prioritize patching the CVE-2026-16232 vulnerability to block incoming attacks.
Intelligence Sources
The Hacker News
2026-07-23
Security Affairs
2026-07-23
BleepingComputer
2026-07-23
Check Point warns of SmartConsole zero-day exploited in attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-23T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
28x
organisation
Identified Entity
Security Management
entity
10x
attribution
Attributing Entity
Check Point Remote Access VPN
authority
6x
infrastructure
Software Version
9.3
version
6x
timeline
Temporal Reference
151.241.99[.]233
158.62.198[.]182
date
5x
vulnerability
Exploited CVE
CVE-2026-16232
cve
3x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
2x
vulnerability
CVSS Score
9
score
2x
general metric
%
54
%
Contextual Telemetry
Context Block
9 METRICS
industry
Targeted Sector
Government
sector
financial
Bod
4
bod
tactic
Cyber Operation Type
Ransomware
tactic
malware
Malware Payload
Qilin
tool
source region
Origin Country
Israel
country
general metric
Binding Operational Directive
26
binding operational directive
general metric
Security Flaw
9
security flaw
general metric
Cvss Score
8
cvss score
general metric
Jul
23
jul
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.