CVE-2026-62144
CVE-2026-16232 is an authentication bypass flaw within the Check Point SmartConsole login process using application token. An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration. This vulnerability is actively exploited. In their investigation, Check Point reported that a very small number of customers were compromised. They found exploitation only affected a very specific configuration, i.e. when Management is exposed directly to the internet without IP restrictions. Affected organisations have been warned by Check Point. CVE-2026-62144 is an authentication bypass and privilege escalation vulnerability in Check Point Management. Successful exploitation allows an unauthenticated attacker to run any command on the Management including run-script and exec-command on Security Gateway (Check Point Firewall). Successful exploitation of this vulnerability requires management access without Firewall protection OR no restrictions on Trusted Clients (GUI clients). CVE-2026-62145 is a local privilege escalation flaw affecting Gaia Portal which allows an authenticated attacker with read-only access to run commands as root.
EPSS 20.62% · 97.3th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Check | Check Point SmartConsole | |
| Gaia | Gaia Portal | |
| Check | Check Point Management |
Timeline
- Jul 22, 2026 Coalition ESS Score
- Jul 22, 2026 CVE Published
- Jul 24, 2026 CVE Updated
- Jul 25, 2026 EPSS Score
References
- https://ccb.belgium.be/advisories/warning-three-privilege-escalation-vulnerabilities-check-point-products-including-1 advisory
- https://support.checkpoint.com/results/sk/sk185169/ vendor
- https://support.checkpoint.com/results/sk/sk185152/ vendor
- https://support.checkpoint.com/results/sk/sk185153/ vendor
- https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232 technical
- https://sc1.checkpoint.com/documents/Check_Point_Gateway_and_Management_Hardening/CP_Check_Point_Gateway_and_Management_Hardening.pdf technical