Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

New Check Point Zero-Day Vulnerability Exploited in the Wild

The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations.

Check Point

Check Point has notified customers that a critical zero-day vulnerability discovered recently in its products has been exploited in the wild.

The exploited vulnerability is tracked as CVE-2026-16232 and it affects the cybersecurity company’s Security Management and Multi-Domain Management products. 

The flaw has been described as an authentication bypass issue that allows an attacker to obtain an application login token. The token can then be used to log in via the SmartConsole with full administrator privileges, and make changes to the security policy and configuration. 

“Check Point confirmed that this vulnerability has been observed in the wild, affecting a handful of customers whose Management environments were directly exposed to the Internet without IP restrictions,” Check Point said.

The security firm has released patches and mitigations, and made available indicators of compromise (IoCs) for the attacks exploiting CVE-2026-16232. Targeted customers have been privately notified.

CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities (KEV) catalog on Wednesday, instructing federal agencies to address it by July 25. 

Advertisement. Scroll to continue reading.

This is the third Check Point vulnerability added to CISA’s KEV list, after CVE-2026-50751, which attackers exploited as a zero-day in May, and CVE-2024-24919, which threat actors leveraged in 2024. 

In addition to CVE-2026-16232, Check Point’s latest updates patch CVE-2026-62144, a critical authentication bypass and privilege escalation flaw affecting Security Management and Multi-Domain Management, and CVE-2026-62145, a high-severity local privilege escalation affecting Firewall, Multi-Domain Management, and Multi-Domain Log Server products. 

All three vulnerabilities were discovered internally by Check Point, but an analysis revealed that CVE-2026-16232 had already been exploited as a zero-day. 

It’s unclear who is behind the latest attacks, but the Qilin ransomware group was recently observed targeting Check Point appliances. 

Related: Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

Related: Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

Related: SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.

John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.

Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.