Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Cybersecurity advisory graphic with shield and warning triangle reading PATCH NOW

A critical zero-day in Check Point’s SmartConsole management interface is being actively exploited to gain full administrator access to firewall management servers.

What’s happening

CVE-2026-16232 is an authentication bypass (CVSS 9.1) affecting Check Point Security Management and Multi-Domain Security Management servers. Unauthenticated attackers can obtain an application login token that grants full admin privileges — letting them rewrite security policies, change VPN configurations, and modify threat prevention settings across every gateway the server manages.

Check Point confirmed exploitation in the wild on 22 July. CISA added it to the Known Exploited Vulnerabilities catalogue on 23 July, requiring US federal agencies to patch by 25 July.

Why it matters for managed environments

The management server isn’t just another admin tool — it’s the trust anchor for the entire Check Point estate. If your MSP or internal IT team runs a single management server across multiple client sites or offices, one compromise can cascade to every gateway under management. Attackers don’t need credentials; they just need the management IP to be reachable without IP restrictions.

This is the second actively exploited Check Point authentication bypass in two months, following CVE-2026-50751 in the Remote Access VPN — a pattern that should prompt any business running Check Point infrastructure to audit their exposure now.

What to do now

  1. Apply the hotfix for R81.20, R82, or R82.10 from Check Point’s security advisory (sk185169).
  2. Restrict Trusted Clients to known IP addresses and block management access from the internet.
  3. Check your audit logs for entries containing “Authentication method: application token” and the IOC IP addresses Check Point has published (including 151.241.99.207, 158.62.198.182, 192.142.10.99, and 139.28.37.250).
  4. If you’re on Smart-1 Cloud, you’re already protected.

Need help checking your Check Point management server? Get in touch — we can audit your exposure and apply the patch.

Sources: BleepingComputer, Help Net Security, Check Point advisory sk185169

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →