Web_Logo
Remote Support
Security Alert: Check Point Firewall Flaw Under Active Attack
Home » Security Alerts  »  Security Alert: Check Point Firewall Flaw Under Active Attack

Security Alert: Check Point Firewall Flaw Under Active Attack

A critical flaw in Check Point's SmartConsole management software is being actively exploited by attackers, letting them gain full administrative control over affected firewalls without a password.

  • What it is: A critical authentication bypass (CVE-2026-16232, CVSS 9.1) in Check Point Security Management and Multi-Domain Management servers, allowing remote attackers to obtain admin access without valid credentials.
  • Who is affected: Businesses running Check Point firewall management infrastructure that has not applied the July 2026 Jumbo Hotfix.
  • The risk: An attacker with admin access can rewrite security policies, disable protections, and open a path into the rest of the network.
  • What to do: Confirm with your IT provider that the 22 July 2026 Jumbo Hotfix has been applied, and restrict management access to trusted IP addresses only.

This vulnerability is already listed on the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalogue, so we recommend treating this patch as urgent rather than routine. More detail is available in Check Point's official advisory.