{"id":16503,"date":"2026-07-23T20:17:21","date_gmt":"2026-07-23T20:17:21","guid":{"rendered":"https:\/\/newestek.com\/?p=16503"},"modified":"2026-07-23T20:17:21","modified_gmt":"2026-07-23T20:17:21","slug":"check-point-hole-grants-unauthenticated-attackers-full-smartconsole-admin-privileges","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16503","title":{"rendered":"Check Point hole grants unauthenticated attackers full SmartConsole admin privileges"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">Check Point has confirmed that a critical security hole in its SmartConsole management tool, one that <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-16232\" target=\"_blank\" rel=\"noreferrer noopener\">allows unauthenticated attackers<\/a> to assume full admin privileges, is now being exploited in the wild. The vulnerability, <a href=\"https:\/\/github.com\/advisories\/ghsa-m2xx-23gx-734v\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-16232<\/a>, was given a CVSS score of 9.3.<\/p>\n<p class=\"wp-block-paragraph\">In its security alert, <a href=\"https:\/\/support.checkpoint.com\/results\/sk\/sk185169\/\" target=\"_blank\" rel=\"noreferrer noopener\">Check Point described<\/a> the bug as one allowing an unauthenticated attacker to \u201cobtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The company has <a href=\"https:\/\/sc1.checkpoint.com\/documents\/Jumbo_HFA\/R82.10\/R82.10\/R82.10-List-of-all-Resolved-Issues.htm\" target=\"_blank\" rel=\"noreferrer noopener\">released a patch<\/a> for the bug and also recommends that users \u201climit Trusted Clients, GUI clients, to trusted IP addresses\/subnets.\u201d That approach has always been a best practice, but practical networking realities today make it challenging to maintain. <a href=\"https:\/\/www.csoonline.com\/article\/4195311\/check-point-cto-jonathan-zanger-sees-ai-elevating-the-value-of-cyber.html\" target=\"_blank\">Check Point<\/a> said that the exploit has impacted ten of its customers, all of whom it had notified directly.<\/p>\n<h2 class=\"wp-block-heading\" id=\"far-worse-than-most\">Far worse than most<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/my.idc.com\/getdoc.jsp?containerId=PRF004767\" target=\"_blank\" rel=\"noreferrer noopener\">Frank Dickson<\/a>, group VP for security at IDC, said this security hole is far worse than most.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis hits harder than your average CVE because of where it lives,\u201d he said. \u201cThe CVE targets the SmartConsole login on Check Point\u2019s Security Management Server, the console that pushes policy to every gateway underneath it. Popping a gateway gets you one lock picked. Popping the management server is more like finding the One Ring: one stolen token to rule every gateway it manages, no need to fight each one individually. The attacker can rewrite policy, open new VPN paths and kill the logging.\u201d<\/p>\n<p class=\"wp-block-paragraph\">In an interview with CSO Online, <a href=\"https:\/\/www.linkedin.com\/in\/lotem-finkelstein-05797a85\/\" target=\"_blank\" rel=\"noreferrer noopener\">Lotem Finkelstein<\/a>, vice president of research at Check Point, said that the company learned of the vulnerability on Sunday, emailed customers the same day, and released the patch within 72 hours.<\/p>\n<p class=\"wp-block-paragraph\">But when his team re-reviewed earlier logs, knowing what to look for, they spotted this hole being attacked as early as April, Finkelstein said.<\/p>\n<p class=\"wp-block-paragraph\">The fact that, over the course of three months, the team only found ten organizations under attack, indicated that it has been very difficult for the attacker to find vulnerable systems, he noted; customers were, in the main, using secure settings to protect themselves.<\/p>\n<p class=\"wp-block-paragraph\">Nonetheless, Finkelstein said, Check Point considers this hole to be \u201ca severe vulnerability.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"challenges-of-ip-address-restrictions\">Challenges of IP address restrictions<\/h2>\n<p class=\"wp-block-paragraph\">While it can be technically challenging to keep the IP address allowlists that Check Point recommends current, given DHCP\u2019s ability to easily change those addresses, <a href=\"https:\/\/www.linkedin.com\/in\/assafmo\/\" target=\"_blank\" rel=\"noreferrer noopener\">Assaf Morag<\/a>, a cybersecurity researcher at Flare, noted that specifically limiting access to a management console is far more critical than limiting overall external access.<\/p>\n<p class=\"wp-block-paragraph\">\u201cImplementing Trusted Clients as a per-IP allowlist is impractical,\u201d he said, but that is not the case with restricting management access. \u201cThe more scalable solution is to restrict access based on trusted administrative network segments such as VPN pools, management VLANs, or jump hosts rather than maintaining lists of individual DHCP-assigned client addresses,\u201d he explained. \u201cThat gives you the security benefit without creating a full-time administrative task. Maintaining allowlists for individual hosts is much more practical when those hosts have stable, predictable IP addresses, rather than dynamically assigned DHCP addresses.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/pieter-arntz-04164b2\/\" target=\"_blank\" rel=\"noreferrer noopener\">Pieter Arntz<\/a>, malware intelligence researcher at Malwarebytes, also noted that the constantly changing nature of global IP addresses can prove annoying to IT teams. Stressing that he is not familiar with Check Point\u2019s specific settings, he noted, \u201cCertain settings are a nuisance when applied strictly, and at some point the IT staff gets tired of constantly tweaking and they abandon the most secure path.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"ideal-platform-for-long-term-attacks\">Ideal platform for long-term attacks<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/eclectiqus\/\" target=\"_blank\" rel=\"noreferrer noopener\">Mike Wilkes<\/a>, enterprise CISO at Aikido Security,\u00a0 agreed that the severity and exposure of this hole is alarming.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis is exactly the kind of vulnerability that keeps CISOs awake at night because it strikes at the one system that is supposed to stand between the attacker and everything else. An authentication bypass that grants administrative control of a perimeter firewall isn\u2019t just another CVE to patch. It\u2019s an invitation for an adversary to rewrite the rules of the network itself,\u201d he said. \u201cThe uncomfortable reality is that nobody runs a CrowdStrike agent on their firewall. Once an attacker owns an edge device, they gain a uniquely privileged position that often falls outside the visibility of traditional endpoint security, making it an ideal platform for persistence, credential theft, traffic manipulation, and long-term espionage.\u201d<\/p>\n<p class=\"wp-block-paragraph\">IDC\u2019s Dickson strongly encouraged CISOs to deploy the patch, not to just change settings to mitigate the issue.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cApply the actual hotfix,\u201d he said. \u201cDon\u2019t just restrict Trusted Client IPs and call it done. That\u2019s a stopgap, not a fix. Any internet-facing management console, Check Point or otherwise, is a five-alarm architecture problem independent of this CVE.\u201d<\/p>\n<p class=\"wp-block-paragraph\">And, he added, \u201csince attackers here can disable logging, audit admin activity going back before the bug surfaced. Quiet logs aren\u2019t proof nothing happened. This is the recurring theme with \u2018single pane of glass\u2019 security tools: the console built to make everything easier to run is also the one thing you really don\u2019t want someone else driving.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Check Point has confirmed that a critical security hole in its SmartConsole management tool, one that allows unauthenticated attackers to assume full admin privileges, is now being exploited in the wild. The vulnerability, CVE-2026-16232, was given a CVSS score of 9.3. In its security alert, Check Point described the bug as one allowing an unauthenticated attacker to \u201cobtain an application login token and use it&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16503\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16503","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16503","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16503"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16503\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16503"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16503"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16503"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}