Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 72.1%top 0.61%

CVE-2026-16232: CWE-287: Improper Authentication. in checkpoint Quantum Security Management

0
Critical
Published: 07/24/2026 (07/24/2026, 21:40:32 UTC)
Source: CVE Database V5
Vendor/Project: checkpoint
Product: Quantum Security Management

Description

Check Point has released urgent security updates addressing three critical vulnerabilities affecting Security Management, Multi-Domain Management, Quantum Security Gateway, and Gaia operating systems. The most severe vulnerability, CVE-2026-16232, allows unauthenticated remote attackers to bypass SmartConsole login and gain full administrative access to exposed Management Servers. The vulnerability has been actively exploited against customers with internet-exposed management infrastructure. Successful exploitation enables attackers to modify firewall policies, create administrator accounts, weaken security protections, and establish persistent access. Two additional vulnerabilities were patched: CVE-2026-62144 enabling unauthenticated command execution, and CVE-2026-62145 allowing privilege escalation from read-only to root access. CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog with an exceptionally short remediation deadline, reflecting the severity of this authentication bypass...

CVSS v4.0

Score 9.3critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 15:01:58 UTC

Technical Analysis

This vulnerability (CWE-287) in Check Point Quantum Security Management's SmartConsole login process permits an unauthenticated remote attacker to bypass authentication controls and obtain an application login token. With this token, the attacker gains full administrative access, allowing modification of security policies and configurations. Exploitation requires network access to the Management Server IP and permissive Trusted Clients settings. Check Point has acknowledged exploitation but has not released an official fix or patch as of the latest information.

Potential Impact

Successful exploitation grants full administrative privileges on the Quantum Security Management system, enabling attackers to alter security policies and configurations. This compromises the confidentiality and integrity of the managed network environment. The vulnerability does not impact system availability but poses a severe risk to network security management.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict internet access to the Management Server IP address and ensure Trusted Clients configurations are properly restricted to prevent unauthorized access. Monitor vendor communications for updates on patches or mitigations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
checkpoint
Date Reserved
2026-07-19T12:14:17.233Z
Cvss Version
null
State
PUBLISHED
Remediation Level
null

Indicators of Compromise

Cve

ValueDescriptionCopy
cveCVE-2026-16232
cveCVE-2026-62144
cveCVE-2026-62145

Ip

ValueDescriptionCopy
ip139.28.37.250
ip151.241.99.207
ip151.241.99.233
ip158.62.198.182

Threat ID: 6a60cec79c2644c7f828494a

Added to database: 07/22/2026, 14:08:07 UTC

Last enriched: 08/14/2026, 15:01:58 UTC

Last updated: 09/04/2026, 04:01:15 UTC

Views: 141

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses