A serious security flaw in Check Point's firewall management software is being actively exploited by hackers right now, letting attackers log in with full administrator rights without needing a password.
- What it is: An authentication bypass (CVE-2026-16232) in Check Point Security Management Server and Multi-Domain Security Management, rated 9.3 out of 10 for severity.
- Who is affected: Any organisation running Check Point Security Management Server or MDS software to control their firewalls.
- What the risk is: A remote attacker can obtain a valid login token and gain complete administrative control over the firewall management console, without any prior access or credentials.
- What action is needed: Businesses using Check Point firewall management should apply the vendor's security patch immediately and review recent admin login activity for anything unusual.
If your business relies on Check Point for network security, we recommend confirming with your IT provider that this patch has been applied without delay.