VDB

CVE-2026-62144

CVE-2026-62144 PUBLISHED CVSS 9.300000190734863 CRITICAL

CVE-2026-16232 is an authentication bypass flaw within the Check Point SmartConsole login process using application token. An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration. This vulnerability is actively exploited. In their investigation, Check Point reported that a very small number of customers were compromised. They found exploitation only affected a very specific configuration, i.e. when Management is exposed directly to the internet without IP restrictions. Affected organisations have been warned by Check Point. CVE-2026-62144 is an authentication bypass and privilege escalation vulnerability in Check Point Management. Successful exploitation allows an unauthenticated attacker to run any command on the Management including run-script and exec-command on Security Gateway (Check Point Firewall). Successful exploitation of this vulnerability requires management access without Firewall protection OR no restrictions on Trusted Clients (GUI clients). CVE-2026-62145 is a local privilege escalation flaw affecting Gaia Portal which allows an authenticated attacker with read-only access to run commands as root.

EPSS 20.62% · 97.3th percentile

Risk Scores

CVSS 3.1
9.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
20.62%
97.3th percentile

Affected Products

VendorProductVersions
CheckCheck Point SmartConsole
GaiaGaia Portal
CheckCheck Point Management

Timeline

  • Jul 22, 2026 Coalition ESS Score
  • Jul 22, 2026 CVE Published
  • Jul 24, 2026 CVE Updated
  • Jul 25, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›