Check Point CVE-2026-16232: full admin on your firewall
An exploited auth bypass in Check Point SmartConsole hands attackers admin on the box that writes your security policy. Patch, then restrict Trusted Clients.
Most critical CVEs let an attacker into a system. CVE-2026-16232 lets them into the system that decides who gets into every other system. It's an authentication bypass in Check Point SmartConsole, it's being exploited in the wild, and a successful attacker doesn't get a shell — they get a full administrator session on your Security Management Server, with the ability to rewrite the security policy your firewalls enforce.
What actually happened
Check Point's advisory sk185169 describes the flaw plainly: an unauthenticated attacker can obtain an application login token and use it to log in via SmartConsole with full admin privileges, including the ability to modify policy. Rapid7 classifies it as improper authentication and rates it critical at CVSS 9.1.
The affected list is long and old: Security Management Server and Multi-Domain Security Management Server across R77.30, R80 through R80.40, R81, R81.10, R81.20, R82, and R82.10. Fixes ship in the Jumbo Hotfix Accumulators — R82.10 from Take 36, R82 from Take 118, R81.20 from Take 158.
Two conditions have to hold for remote exploitation: the Management Server IP is reachable from the internet, and Trusted Clients (GUI clients) is not restricted to specific addresses. Check Point confirmed a small number of customers were targeted and published IPs associated with the attacks. CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog on July 22, with a July 25 remediation deadline for federal agencies — the tightest window CISA hands out.
Why your management plane matters for your business
"Reachable from the internet, no IP restriction on Trusted Clients" is not an exotic misconfiguration. It's what you get when someone needed to manage the firewall from home once, opened it up, and never closed it. If your network was set up by a departed IT contractor or is currently held by an MSP, nobody at your company knows which of those two conditions is true right now.
So the work here is short and it isn't only patching. Apply the Jumbo HFA for your release train. Set Trusted Clients to specific IPs or subnets — never "Any." Put the Management Server behind firewall rules that only permit management traffic from addresses you name. Then check the published attacker IPs against your management logs, because the patch fixes the door and tells you nothing about whether someone already walked through it and edited a rule.
The broader lesson is the one we keep repeating in these posts. Management planes — firewall consoles, RMM, hypervisor UIs, backup admin — are the highest-value targets you own, and they're the ones most likely to be quietly exposed because exposing them made someone's Tuesday easier. Inventory them. None of them belong on the open internet.
Key takeaways
- CVE-2026-16232 is an actively exploited authentication bypass giving unauthenticated attackers full admin on Check Point management servers
- Rapid7 rates it CVSS 9.1; CISA added it to the KEV catalog July 22 with a July 25 federal deadline
- Fixes are in Jumbo HFA R82.10 Take 36, R82 Take 118, and R81.20 Take 158
- Exploitation requires an internet-reachable Management Server and unrestricted Trusted Clients — fix both, don't just patch
- Check the attacker IPs Check Point published against your management logs; a patch doesn't tell you whether policy was already changed
Nobody at your company knows what's exposed? We inventory the management planes — firewalls, RMM, hypervisors, backups — confirm what's reachable from outside, and get the answer in writing from whoever runs them. Book an exposure audit or see how we harden small-business infrastructure.
Sources: Check Point sk185169, Rapid7, BleepingComputer.
- #cve-2026-16232
- #check-point
- #firewall
- #patch-management
- #attack-surface
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Qualcomm's price increase hits your hardware budget
Qualcomm told customers of a double-digit price increase on chips shipped after September 1. The AI buildout is now repricing hardware that has nothing to do with AI.
Read it24,000 exposed BMCs leak hashes: close your IPMI port
A 2004 protocol flaw with no patch is handing out password hashes from 24,000 internet-exposed server BMCs. The fix is network exposure, not a firmware update.
Read it